Description
The application opens a PDF containing an abnormal color space whose attributes reference a valid but semantically malformed function. The function's output is not validated; when subsequently read, it produces an illegal pointer that accesses an out-of-bounds region, crashing the application.
Published: 2026-07-08
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises when Foxit PDF Editor or Reader processes a PDF that contains an abnormal color space whose attributes reference a semantically malformed function. The application does not validate the function’s output; when the value is later read the parser creates an illegal pointer that accesses memory outside the valid bounds, causing the program to crash. This out‑of‑bounds read (CWE‑125) results in a denial‑of‑service failure, terminating the PDF viewer without compromising the underlying system or leaking sensitive data.

Affected Systems

The flaw affects Foxit Software Inc.’s PDF products, namely Foxit PDF Editor and Foxit PDF Reader. The advisory does not provide a specific affected version range, implying that any build released without the patch could be vulnerable.

Risk and Exploitability

With a CVSS score of 6.1, the issue is classified as moderate; the EPSS score of < 1% indicates a very low probability of exploitation, and it is not listed in the CISA KEV catalog. The likely attack vector is that an attacker crafts a malicious PDF and entices a user to open it. Successful exploitation leads to a crash, impacting service availability but not granting elevation of privilege or data leakage. The overall risk therefore depends on the frequency of exposure to malicious PDFs and the importance of the PDF viewer in the organization’s workflows.

Generated by OpenCVE AI on July 25, 2026 at 20:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Foxit PDF Editor and Foxit PDF Reader to the latest releases that include the patched color space handling.
  • Disable automatic opening or execution of PDF content by default and configure the viewer to treat unknown PDFs as read‑only or view them in a sandboxed mode.
  • Regularly review Foxit’s security bulletins and apply any new patches or advisories as they become available.

Generated by OpenCVE AI on July 25, 2026 at 20:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader
Vendors & Products Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader

Wed, 08 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Description The application opens a PDF containing an abnormal color space whose attributes reference a valid but semantically malformed function. The function's output is not validated; when subsequently read, it produces an illegal pointer that accesses an out-of-bounds region, crashing the application.
Title Security vulnerability in Foxit PDF Editor/Reader — OOB Read via NaN-Bypass Clamp
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H'}


Subscriptions

Foxitsoftware Foxit Pdf Editor Foxit Reader
cve-icon MITRE

Status: PUBLISHED

Assigner: Foxit

Published:

Updated: 2026-07-08T12:46:48.415Z

Reserved: 2026-06-24T03:01:18.718Z

Link: CVE-2026-57255

cve-icon Vulnrichment

Updated: 2026-07-08T12:46:42.465Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-25T21:00:14Z

Weaknesses