Junglewise Threat Intelligence

CVE-2026-57256: Foxit PDF Editor use after free in list box field JavaScript processing

CVE-2026-57256 · Severity: high · CVSS 7.8 · Published 2026-07-08

Executive brief

Foxit PDF Reader and Editor are widely used applications for viewing and managing PDF documents. A vulnerability has been identified where opening a specially crafted PDF file containing malicious JavaScript can cause the application to crash or allow an attacker to execute unauthorized code. This could lead to a full system compromise or the theft of sensitive information if a user is tricked into opening a malicious document.

Technical details

A use-after-free (CWE-416) vulnerability exists in Foxit PDF Reader and Editor when handling list box fields in PDF forms. The flaw is triggered when the application executes JavaScript that performs abnormal operations on a list box, particularly during form reset actions. The application fails to adequately verify the validity of form objects and their internal dictionary pointers, leading to an illegal pointer read or access to improperly initialized fields. An attacker can exploit this by enticing a user to open a malformed PDF, resulting in a crash or potential remote code execution. The issue is addressed in version 2026.1.2.

Affected products

  • Foxit Software Inc. Foxit PDF Editor 2026.1.1 and earlier, 14.0.4 and earlier, 13.2.4 and earlier
  • Foxit Software Inc. Foxit PDF Reader 2026.1.1 and earlier

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: advisory
  • 2026-07-08: patched

References