Description
The application opens the PDF, and JavaScript modifies the form. However, the related objects on the page lack complete lifecycle management and null value validation; when the page state changes, the application continuously dereferences invalid objects, eventually leading to a crash.
Published: 2026-07-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Foxit PDF Editor and Reader crash when a PDF containing embedded JavaScript modifies a form. The JavaScript alters form elements, but the application fails to manage the lifecycle of the affected PDF objects or validate null references. This path leads to a use‑after‑free error that terminates the process, CWE‑416, reflecting unsafe memory reference after deallocation.

Affected Systems

The vulnerability affects Foxit Software Inc.'s PDF Editor and PDF Reader applications. No specific versions are disclosed, so any installation of these products remains potentially affected until a vendor patch that addresses the use‑after‑free bug is applied.

Risk and Exploitability

The CVSS score of 7.8 classifies the issue as high severity. The EPSS score is reported as < 1%, indicating a very low chance of exploitation at this time. The vulnerability does not appear in the CISA KEV catalog. Based on the description, the likely attack vector involves delivering a malicious PDF that contains JavaScript to modify a form; the victim must open the PDF in Foxit Editor or Reader. A remote or local attacker who can send the PDF to a user or embed it in a document management system can processes.

Generated by OpenCVE AI on July 29, 2026 at 14:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Foxit update that resolves the use‑after‑free error.
  • If a patch is not yet available, disable JavaScript support or enable safe‑mode processing for PDF files to prevent script execution that could trigger the flaw.
  • Process untrusted PDF files in a sandboxed or isolated environment to contain any application crash and protect the host operating system.

Generated by OpenCVE AI on July 29, 2026 at 14:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader
Vendors & Products Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader

Wed, 08 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Description The application opens the PDF, and JavaScript modifies the form. However, the related objects on the page lack complete lifecycle management and null value validation; when the page state changes, the application continuously dereferences invalid objects, eventually leading to a crash.
Title Foxit PDF Editor/Reader Page Use-After-Free Vulnerability
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Foxitsoftware Foxit Pdf Editor Foxit Reader
cve-icon MITRE

Status: PUBLISHED

Assigner: Foxit

Published:

Updated: 2026-07-08T13:16:35.128Z

Reserved: 2026-06-24T03:01:15.648Z

Link: CVE-2026-57242

cve-icon Vulnrichment

Updated: 2026-07-08T13:16:29.493Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T14:45:02Z

Weaknesses