Junglewise Threat Intelligence

CVE-2026-91790: Foxit PDF Reader use-after-free in image rendering

CVE-2026-91790 · Severity: high · CVSS 7.8 · Published 2026-09-23

Technologies: Foxit PDF Reader, Foxit PDF Editor. Vendors: Foxit.

Executive brief

Foxit PDF Reader and PDF Editor fail to properly validate image objects in PDF documents, which can cause the application to crash when processing specially crafted files. An attacker could exploit this vulnerability by sending a malicious PDF that triggers a use-after-free condition, resulting in application denial of service or potential code execution.

Technical details

A use-after-free vulnerability exists in the image rendering component when processing PDF objects with malformed optional content attributes. The application fails to validate these attributes before accessing internal data structures, leading to access of freed memory. The vulnerability requires user interaction (opening a malicious PDF) and is exploitable via a local attack vector.

Affected products

  • Foxit PDF Reader 2026.2.0.39747 and earlier
  • Foxit PDF Editor 2026.2.0.39747 and all previous 2026.x versions, 2025.3.0.35737 and all previous 2025.x versions, 2024.4.1.27687 and all previous 2024.x versions, 2023.3.0.23028 and all previous 2023.x versions, 14.0.7.33751 and all previous 14.x versions, 13.2.6.24111 and earlier

Timeline

  • 2026-09-23: disclosed
  • 2026-09-23: patched: Foxit PDF Reader 2026.2.1 and Foxit PDF Editor 2026.2.1/14.0.8

References

Related threats