FoxitCVE-2026-57244
Foxit PDF: use after free
High7.8CVE-2026-57244 · Published Jul 8, 2026 · updated Jul 9, 2026
After JavaScript resetting the form, the synchronization process lacks re-entry protection and object lifecycle verification, resulting in the failure of the control pointer during the traversal process. After the pointer fails, it still continues to dereference, causing the application to crash.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Foxit PDF Editor Product | <= Versions 2026.1.1 and earlier | No fix yet |
| <= Versions 14.0.4 and earlier | No fix yet | |
| <= Versions 13.2.4 and earlier | No fix yet | |
| <= Versions 2026.1.1 and earlier | No fix yet | |
| <= Versions 14.0.3 and earlier | No fix yet | |
| <= Versions 13.2.3 and earlier | No fix yet | |
| Foxit PDF Reader Product | <= Versions 2026.1.1 and earlier | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-416
More Foxit advisories
All Foxit| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 8 | Foxit PDF: out-of-bounds read | Medium6.1 | No fix yet |
| Jul 8 | Foxit PDF: XML external entity | Medium6.5 | No fix yet |
| Jul 8 | Foxit PDF: out-of-bounds write | High7.8 | No fix yet |
| Jul 8 | Foxit PDF: use after free | High7.8 | No fix yet |
| Jul 8 | Foxit PDF: improper array index validation | High7.8 | No fix yet |
| Jul 8 | Foxit PDF: use after free | High7.8 | No fix yet |