CVE-2026-57254
Analyzed Analyzed - Analysis Complete

PDF Annotation Type Confusion Leading to Application Crash

Vulnerability report for CVE-2026-57254, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-08

Last updated on: 2026-07-09

Assigner: Foxit

Description

There is an abnormal annotation within the PDF that is referenced by other objects. When the application parses the PDF, it fails to perform proper type checking, ultimately causing the application to crash.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-08
Last Modified
2026-07-09
Generated
2026-07-15
AI Q&A
2026-07-09
EPSS Evaluated
2026-07-14
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
foxit pdf_editor From 2023.1.0.15510 (inc) to 2023.3.0.23028 (inc)
foxit pdf_editor From 2024.1.0.23997 (inc) to 2024.4.1.27687 (inc)
foxit pdf_editor From 2025.1.0.27937 (inc) to 2025.3.0.35737 (inc)
foxit pdf_editor From 2026.1.0.36452 (inc) to 2026.1.1.36485 (inc)
foxit pdf_reader to 2026.1.1.36485 (inc)
foxit pdf_editor to 13.2.4.24048 (inc)
foxit pdf_editor From 14.0.0.33046 (inc) to 14.0.4.33508 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-843 The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Compliance Impact

The provided information does not specify how this vulnerability impacts compliance with common standards and regulations such as GDPR or HIPAA.

Mitigation Strategies

To mitigate this vulnerability, users are advised to update their Foxit PDF Reader and Editor applications to the latest versions.

The updates can be obtained through the application’s built-in update feature or by downloading the latest versions from the Foxit website.

Executive Summary

This vulnerability involves an abnormal annotation within a PDF file that is referenced by other objects. When an application parses this PDF, it does not perform proper type checking on the annotation, which leads to the application crashing.

Impact Analysis

The vulnerability can cause the affected application to crash when processing a specially crafted PDF file. This can lead to denial of service, disrupting normal operations and potentially causing loss of availability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-57254. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart