FoxitCVE-2026-57238
Foxit PDF: use after free
High7.8CVE-2026-57238 · Published Jul 8, 2026 · updated Jul 9, 2026
After the application opened the PDF, JavaScript deleted the form field object. Subsequently, it attempted to access the invalid object, which caused the application to crash.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Foxit PDF Editor Product | <= Versions 2026.1.1 and earlier | No fix yet |
| <= Versions 14.0.4 and earlier | No fix yet | |
| <= Versions 13.2.4 and earlier | No fix yet | |
| Foxit PDF Reader Product | <= Versions 2026.1.1 and earlier | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-416
More Foxit advisories
All Foxit| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 8 | Foxit PDF: out-of-bounds read | Medium6.1 | No fix yet |
| Jul 8 | Foxit PDF: XML external entity | Medium6.5 | No fix yet |
| Jul 8 | Foxit PDF: out-of-bounds write | High7.8 | No fix yet |
| Jul 8 | Foxit PDF: use after free | High7.8 | No fix yet |
| Jul 8 | Foxit PDF: improper array index validation | High7.8 | No fix yet |
| Jul 8 | Foxit PDF: use after free | High7.8 | No fix yet |