Description
During the process of page opening and form formatting, a JavaScript reentrancy results in an inconsistent document status. Subsequently, with outdated page information, the application attempts to access invalid addresses, causing the application to crash.
Published: 2026-07-08
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

During the opening and formatting of a page, Foxit PDF Editor or Reader processes JavaScript in a way that creates a reentrancy condition. This leads to an inconsistent internal document status, after which the application attempts to read from invalid memory addresses. The out‑of‑bounds read (CWE‑125) causes the program to crash, resulting in a denial of service for the user or local system.

Affected Systems

Foxit Software Inc.'s Foxit PDF Editor and Foxit PDF Reader products are affected. Affected versions are not specified, so it is unclear which releases are vulnerable; any version could be affected pending official vendor guidance.

Risk and Exploitability

The CVSS score of 6.1 indicates a moderate severity. The EPSS score of <1% and the absence of this vulnerability from the CISA KEV catalogue suggest a low likelihood of current exploitation. Based on the description, it is inferred that an attacker would embed malicious JavaScript into a PDF document and entice a user to open it, triggering the reentrancy and causing the crash. Since the flaw only causes a denial of service and does not provide code execution, the threat is limited to service disruption for the target user.

Generated by OpenCVE AI on July 29, 2026 at 14:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the available Foxit security patch or update to the latest version as soon as released.
  • Use a sandboxed or protected PDF viewer to minimize exposure to malicious PDFs.
  • Avoid opening PDFs from untrusted sources until the vendor releases a fix.

Generated by OpenCVE AI on July 29, 2026 at 14:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader
Vendors & Products Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader

Wed, 08 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Description During the process of page opening and form formatting, a JavaScript reentrancy results in an inconsistent document status. Subsequently, with outdated page information, the application attempts to access invalid addresses, causing the application to crash.
Title Foxit PDF Editor/Reader Page Out-of-bounds Read Vulnerability
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H'}


Subscriptions

Foxitsoftware Foxit Pdf Editor Foxit Reader
cve-icon MITRE

Status: PUBLISHED

Assigner: Foxit

Published:

Updated: 2026-07-08T13:16:09.439Z

Reserved: 2026-06-24T03:01:15.648Z

Link: CVE-2026-57243

cve-icon Vulnrichment

Updated: 2026-07-08T13:16:05.138Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T14:45:02Z

Weaknesses