Description
A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of wide strings in embedded PDF JavaScript. Insufficient validation of string-deletion ranges can cause an integer underflow, resulting in an out-of-bounds read and application crash.
Published: 2026-09-23
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (application crash)
Action: Patch Update
AI Analysis

Impact

A heap‑based out‑of‑bounds read occurs in Foxit PDF Editor/Reader when handling wide strings inside embedded PDF JavaScript. The flaw arises from inadequate validation of string‑deletion ranges, which can trigger an integer underflow. This leads to a read beyond the bounds of a heap buffer and causes the application to terminate unexpectedly. The vulnerability does not directly allow code execution, but the crash could be leveraged in a broader exploit chain or used as a denial‑of‑service vector.

Affected Systems

The issue affects both Foxit PDF Editor and Foxit PDF Reader from Foxit Software Inc. The CVE does not enumerate specific product revisions, implying that all publicly released versions that parse embedded PDF JavaScript are susceptible.

Risk and Exploitability

The CVSS score of 6.1 reflects a moderate severity, while the EPSS score of less than 1% indicates a low likelihood of active exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. It is likely to be exploited by attackers who craft malicious PDF files with malicious JavaScript, hoping to crash the target application. Because the flaw is limited to a buffer read and does not expose a clear control‑flow hijack, the overall risk is moderate, but the impact on user experience and potential for cascading failures warrants attention.

Generated by OpenCVE AI on September 23, 2026 at 15:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available Foxit patch that addresses the heap‑based read flaw.
  • Disable JavaScript execution for PDF documents or run Foxit in safe mode to avoid processing embedded scripts.
  • Monitor crash logs for repeated termination events and block or quarantine offending PDF files.
  • If possible, use network filtering to prevent delivery of malicious PDF attachments to user systems.

Generated by OpenCVE AI on September 23, 2026 at 15:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of wide strings in embedded PDF JavaScript. Insufficient validation of string-deletion ranges can cause an integer underflow, resulting in an out-of-bounds read and application crash.
Title Foxit PDF Editor/Reader AcroForm Out-of-Bounds Read Remote Code Execution Vulnerability
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Foxit

Published:

Updated: 2026-09-23T14:22:36.779Z

Reserved: 2026-09-15T07:34:45.816Z

Link: CVE-2026-91817

cve-icon Vulnrichment

Updated: 2026-09-23T14:22:05.705Z

cve-icon NVD

Status : Received

Published: 2026-09-23T08:17:14.010

Modified: 2026-09-23T15:17:28.437

Link: CVE-2026-91817

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T15:30:07Z

Weaknesses