FoxitCVE-2026-13128
Foxit PDF: use after free
High7.8CVE-2026-13128 · Published Jul 8, 2026 · updated Jul 9, 2026
Embedding JavaScript within a PDF file will cause the page to be deleted. Subsequent scripts will continue to access the relevant properties of the document view, eventually leading to the crash of the application.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Foxit PDF Editor Product | <= Versions 2026.1.1 and earlier | No fix yet |
| Foxit PDF Reader Product | <= Versions 2026.1.1 and earlier | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-416
More Foxit advisories
All Foxit| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 8 | Foxit PDF: out-of-bounds read | Medium6.1 | No fix yet |
| Jul 8 | Foxit PDF: XML external entity | Medium6.5 | No fix yet |
| Jul 8 | Foxit PDF: out-of-bounds write | High7.8 | No fix yet |
| Jul 8 | Foxit PDF: use after free | High7.8 | No fix yet |
| Jul 8 | Foxit PDF: improper array index validation | High7.8 | No fix yet |
| Jul 8 | Foxit PDF: use after free | High7.8 | No fix yet |