Description
When the application opens a PDF and JavaScript modifies the properties of form fields, it causes the state of the underlying objects referenced by the program to become invalid. Eventually, it reads an illegal memory address, which leads to the crash of the application.
Published: 2026-07-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Foxit PDF Editor and PDF Reader contain a use‑after‑free weakness that is triggered when JavaScript modifies the properties of form fields in a PDF document. The program fails to invalidate or correctly re‑reference the underlying objects, leading to a read of an illegal memory address and an application crash. This outcome is a denial of service; the available information does not indicate that arbitrary code execution can be achieved.

Affected Systems

Foxit Software Inc. offers the vulnerable products. The Foxit PDF Editor and Foxit PDF Reader are affected. No specific version information is supplied, so users should verify whether their installations contain the fix or upgrade to the latest releases from Foxit.

Risk and Exploitability

The CVSS base score of 7.8 reflects a high‑severity flaw that impacts availability. The EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Attackers would most likely embed a malicious PDF containing JavaScript that alters form fields and deliver it through phishing emails or compromised websites, aiming to cause the application to crash when a user opens the file. No evidence suggests that the flaw can be leveraged for remote code execution or privilege escalation.

Generated by OpenCVE AI on July 29, 2026 at 14:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the most recent Foxit PDF Editor or Foxit PDF Reader patch that resolves the use‑after‑free flaw.
  • Configure the application to disable or restrict JavaScript execution in PDFs so that malicious scripts cannot modify form field properties.
  • Inspect PDF files received from untrusted sources and quarantine or delete any that contain unexpected JavaScript or annotations before opening them in the application.

Generated by OpenCVE AI on July 29, 2026 at 14:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader
Vendors & Products Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader

Wed, 08 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Description When the application opens a PDF and JavaScript modifies the properties of form fields, it causes the state of the underlying objects referenced by the program to become invalid. Eventually, it reads an illegal memory address, which leads to the crash of the application.
Title Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Foxitsoftware Foxit Pdf Editor Foxit Reader
cve-icon MITRE

Status: PUBLISHED

Assigner: Foxit

Published:

Updated: 2026-07-08T13:15:21.343Z

Reserved: 2026-06-24T03:01:15.648Z

Link: CVE-2026-57237

cve-icon Vulnrichment

Updated: 2026-07-08T13:15:14.700Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T14:45:02Z

Weaknesses