CVE-2026-91808
Received Received - Intake

Heap Out-of-Bounds Read in Foxit PDF Editor

Vulnerability report for CVE-2026-91808, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: Foxit

Description

A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor Reader’s handling of PDF image objects with inconsistent compression metadata. Insufficient validation during image decoding may result in an undersized buffer and an out-of-bounds read during rendering, causing an application crash.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-23
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
foxit pdf_editor_reader *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a heap-based out-of-bounds read vulnerability in Foxit PDF Editor Reader. It occurs when the application processes PDF image objects with inconsistent compression metadata. The software fails to validate the metadata properly during image decoding, leading to an undersized buffer. This causes the application to read memory outside the intended buffer while rendering the PDF, which can crash the application.

Detection Guidance

This vulnerability involves a heap-based out-of-bounds read in Foxit PDF Editor Reader during PDF image object processing. Detection requires inspecting PDF files for inconsistent compression metadata in image objects. Use Foxit's built-in update checks or monitor for crashes during PDF rendering. No specific commands are provided in the context to directly detect this issue.

Impact Analysis

If exploited, this vulnerability could allow an attacker to crash the Foxit PDF Editor Reader application when you open a specially crafted PDF file. This could lead to denial of service, disrupting your ability to view or edit PDFs. It may also potentially expose limited memory contents, though no direct code execution is indicated.

Compliance Impact

This vulnerability may impact compliance with GDPR and HIPAA by potentially exposing sensitive data through application crashes caused by out-of-bounds reads. Such crashes could lead to unauthorized access or disclosure of personal or health information during rendering of malformed PDFs.

Mitigation Strategies

Update Foxit PDF Editor Reader to the latest version to patch the vulnerability. Avoid opening untrusted PDF files, especially those with image objects. Disable PDF rendering in email clients or web browsers if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91808. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart