Description
When the application opens a PDF and JavaScript resets the form fields, the script re-enters the interface. The underlying native object is damaged, but the application does not perform validation. The function call on the damaged object leads to the application crashing.
Published: 2026-07-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a use‑after‑free bug that occurs when a PDF file containing JavaScript resets form fields. The application does not validate the freed native object, and the subsequent function call crashes the program, resulting in a denial‑of-service condition on the device that opens the file. The weakness is identified as CWE‑416.

Affected Systems

Foxit Software Inc. publishes Foxit PDF Editor and Foxit PDF Reader. No specific version numbers are provided; any installation of these applications may be vulnerable unless a newer release with the fix is installed.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, but the EPSS score of less than 1% suggests a very low exploitation likelihood as of the latest data. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is embedding malicious JavaScript that resets form fields within a PDF file; a victim who opens such a file causes the application to crash, providing an insecure environment for attackers that rely on denial of service.

Generated by OpenCVE AI on July 28, 2026 at 09:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest Foxit package that fixes the use‑after‑free flaw in PDF handling when JavaScript support is required.
  • Disable JavaScript processing in Foxit settings or use a viewer that ignores script execution.
  • Scan inbound PDF files with anti‑malware solutions and block attachments that trigger known dangerous scripts.

Generated by OpenCVE AI on July 28, 2026 at 09:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader
Vendors & Products Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader

Wed, 08 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Description When the application opens a PDF and JavaScript resets the form fields, the script re-enters the interface. The underlying native object is damaged, but the application does not perform validation. The function call on the damaged object leads to the application crashing.
Title Foxit PDF Editor/Reader Form Field Use-After-Free Vulnerability
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Foxitsoftware Foxit Pdf Editor Foxit Reader
cve-icon MITRE

Status: PUBLISHED

Assigner: Foxit

Published:

Updated: 2026-07-08T13:13:58.987Z

Reserved: 2026-06-24T03:01:18.717Z

Link: CVE-2026-57250

cve-icon Vulnrichment

Updated: 2026-07-08T13:13:54.739Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T09:30:19Z

Weaknesses