Description
After JavaScript resetting the form, the synchronization process lacks re-entry protection and object lifecycle verification, resulting in the failure of the control pointer during the traversal process. After the pointer fails, it still continues to dereference, causing the application to crash.
Published: 2026-07-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Foxit Software’s PDF Editor and Reader contain a use‑after‑free flaw that occurs when JavaScript code resets form. This is a CWE‑416 use‑after‑free flaw. The synchronization logic does not guard against re‑entry or verify the object’s lifecycle, so the control pointer becomes invalid. The subsequent dereference causes the application to crash, denying service to legitimate users. This issue does not provide an attacker with remote code execution or data exfiltration capabilities, but it can be used to disrupt operations by causing the application to terminate unexpectedly.

Affected Systems

Foxit PDF Editor and Foxit PDF Reader on all platforms form control component is present listed for the vulnerability, so any installation that includes the form control is potentially affected.

Risk and Exploitability

The CVSS score of 7.8 classifies the flaw as high severity, and the EPSS score of < 1% indicates a very low probability that a vulnerability will be exploited in the wild. The vulnerability is not listed in CISA's KEV in the wild. Based on the description, it is inferred that attackers can trigger the flaw by supplying a PDF file containing malicious JavaScript that resets a form. The likely attack vector is local exploitation via a crafted PDF opened by a user, or remote delivery through email or a web link. The lack of a known exploitation method and the KEV status reduce the immediate risk, but the DoS impact warrants prompt remediation.

Generated by OpenCVE AI on July 29, 2026 at 14:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Foxit PDF Editor or Reader to the latest the use‑after‑free flaw.
  • If an upgrade is not immediately possible, disable JavaScript execution in Foxit’s security settings to prevent the form reset code from running.
  • As a temporary measure, remove or disable the form control feature for users who require it least, or monitor PDF files with signature verification before opening.

Generated by OpenCVE AI on July 29, 2026 at 14:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader
Vendors & Products Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader

Wed, 08 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Description After JavaScript resetting the form, the synchronization process lacks re-entry protection and object lifecycle verification, resulting in the failure of the control pointer during the traversal process. After the pointer fails, it still continues to dereference, causing the application to crash.
Title Foxit PDF Editor/Reader Form Control Use-After-Free Vulnerability
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Foxitsoftware Foxit Pdf Editor Foxit Reader
cve-icon MITRE

Status: PUBLISHED

Assigner: Foxit

Published:

Updated: 2026-07-08T13:14:51.433Z

Reserved: 2026-06-24T03:01:15.649Z

Link: CVE-2026-57244

cve-icon Vulnrichment

Updated: 2026-07-08T13:14:47.168Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T14:45:02Z

Weaknesses