Description
During the PRC parsing stage, there is a lack of boundary verification for the PRC entity index, which leads to an out-of-bounds read of the entity array. As a result, the application crashes.
Published: 2026-07-08
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

During the PRC parsing stage in Foxit PDF Editor and Reader, a missing boundary check on the PRC entity index allows an out‑of‑bounds read of the entity array, causing the application to crash. Because the flaw does not leak data or allow code execution, the primary impact is a denial of service that can interrupt business processes when a malicious PDF is opened.

Affected Systems

Foxit PDF Editor and Foxit PDF Reader from Foxit Software Inc. Version details were not disclosed in the advisory, so all pre‑patch releases remain vulnerable.

Risk and Exploitability

The CVSS score of 6.1 classifies the vulnerability as medium severity, while the EPSS score (<1%) indicates a very low likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog, suggesting no known active exploitation. The most probable attack vector is an adversary supplying a crafted PDF containing a malicious PRC section crashes, resulting in service disruption rather than remote code execution.

Generated by OpenCVE AI on July 29, 2026 at 14:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest release of Foxit PDF Editor or Foxit PDF Reader, which includes validation of the PRC entity index.
  • Until a patch is available, run Foxit PDF applications in a sandbox or with reduced privileges to contain any crash.
  • Implement a policy that restricts opening PDFs from untrusted sources and consider using PDF sanitization tools to reject malformed documents.

Generated by OpenCVE AI on July 29, 2026 at 14:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader
Vendors & Products Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader

Wed, 08 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Description During the PRC parsing stage, there is a lack of boundary verification for the PRC entity index, which leads to an out-of-bounds read of the entity array. As a result, the application crashes.
Title Security vulnerability in Foxit PDF Editor/Reader — PRC 3D BRep Renderer Heap OOB Read
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H'}


Subscriptions

Foxitsoftware Foxit Pdf Editor Foxit Reader
cve-icon MITRE

Status: PUBLISHED

Assigner: Foxit

Published:

Updated: 2026-07-08T12:39:33.187Z

Reserved: 2026-06-24T03:01:24.249Z

Link: CVE-2026-57257

cve-icon Vulnrichment

Updated: 2026-07-08T12:39:30.149Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T14:45:02Z

Weaknesses