FoxitCVE-2026-18597
Foxit PDF Services API: server-side request forgery
High8.5CVE-2026-18597 · Published Aug 6, 2026 · updated Aug 26, 2026
The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is restricted, an attacker could trigger an SSRF vulnerability by using URL redirection to bypass validation, leading to information disclosure.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Foxit PDF Services API Product | <= before 2026-07-27 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-918
More Foxit advisories
All Foxit| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 13 | Foxit PDF Editor/Reader inconsistently alerts users | Medium4.7 | No fix yet |
| Jul 8 | Foxit PDF: out-of-bounds read | Medium6.1 | No fix yet |
| Jul 8 | Foxit PDF: XML external entity | Medium6.5 | No fix yet |
| Jul 8 | Foxit PDF: out-of-bounds write | High7.8 | No fix yet |
| Jul 8 | Foxit PDF: use after free | High7.8 | No fix yet |
| Jul 8 | Foxit PDF: improper array index validation | High7.8 | No fix yet |