Description
The PRC file header parsing logic trusts the constructed file structure description information, assumes that the underlying array contains elements and reads them, leading to out-of-bounds reads and application crashes.
Published: 2026-07-08
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The PRC file header parser in Foxit PDF Editor and Foxit PDF Reader incorrectly trusts the constructed file structure description, assumes the underlying array contains elements, and reads past the array bounds. When a PDF containing a maliciously crafted PRC 3D stream is opened, the application attempts an out‑of‑bounds read, causing the program to terminate, resulting in a denial of service for the current user session.

Affected Systems

Foxit Software Inc.'s Foxit PDF Editor and Foxit PDF Reader are affected. Version information has not been published, so all releases until the next vendor update should be considered vulnerable.

Risk and Exploitability

The CVSS score of 6.1 classifies the flaw as moderate risk, while an EPSS score of < 1% indicates a very low likelihood of exploitation. The observed effect is a crash, causing a denial of service on the user session. The issue is not listed in the CISA KEV catalog, further diminishing the current threat weight.

Generated by OpenCVE AI on July 29, 2026 at 14:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch when it becomes available.
  • Restrict handling of PDF files from unknown or untrusted sources, such as disabling automatic opening or running the viewer in a sandbox.
  • Monitor application crash logs or use performance monitoring to detect repeated crashes, and update the patch promptly.

Generated by OpenCVE AI on July 29, 2026 at 14:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader
Vendors & Products Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader

Wed, 08 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Description The PRC file header parsing logic trusts the constructed file structure description information, assumes that the underlying array contains elements and reads them, leading to out-of-bounds reads and application crashes.
Title Foxit PDF Editor/Reader Crash via Malformed PRC 3D Stream
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H'}


Subscriptions

Foxitsoftware Foxit Pdf Editor Foxit Reader
cve-icon MITRE

Status: PUBLISHED

Assigner: Foxit

Published:

Updated: 2026-07-08T12:40:12.497Z

Reserved: 2026-06-24T03:01:24.249Z

Link: CVE-2026-57258

cve-icon Vulnrichment

Updated: 2026-07-08T12:40:09.160Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T14:45:02Z

Weaknesses