FoxitCVE-2026-13127
Foxit PDF: use after free
High7.8CVE-2026-13127 · Published Jul 8, 2026 · updated Jul 9, 2026
The application opens the PDF file. JavaScript then rewrites the document to modify the page structure, resulting in the invalidation of the page objects. However, the thumbnails still use the invalid page objects, ultimately causing the application to crash.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Foxit PDF Editor Product | <= Versions 2026.1.1 and earlier | No fix yet |
| <= Versions 14.0.4 and earlier | No fix yet | |
| <= Versions 13.2.4 and earlier | No fix yet | |
| Foxit PDF Reader Product | <= Versions 2026.1.1 and earlier | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-416
More Foxit advisories
All Foxit| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 8 | Foxit PDF: out-of-bounds read | Medium6.1 | No fix yet |
| Jul 8 | Foxit PDF: XML external entity | Medium6.5 | No fix yet |
| Jul 8 | Foxit PDF: out-of-bounds write | High7.8 | No fix yet |
| Jul 8 | Foxit PDF: use after free | High7.8 | No fix yet |
| Jul 8 | Foxit PDF: improper array index validation | High7.8 | No fix yet |
| Jul 8 | Foxit PDF: use after free | High7.8 | No fix yet |