Executive brief
Foxit PDF Editor and Reader are widely used applications for viewing and editing PDF documents in business environments. A use-after-free vulnerability in the PDF page-tree handling allows an attacker to craft a malicious PDF that crashes the application and potentially corrupts memory. An attacker could exploit this by distributing a specially crafted PDF file, causing denial of service and potentially enabling further attacks.
Technical details
The vulnerability is a use-after-free in PDF page-tree handling triggered by page-structure changes during rendering. An attacker can craft a malicious PDF file that causes the application to access released page objects, resulting in memory corruption and application crashes. The attack requires only user interaction (opening the PDF) with no authentication or special privileges required.
Affected products
- Foxit PDF Reader 2026.2.0.39747 and earlier
- Foxit PDF Editor 2026.2.0.39747 and all previous 2026.x versions, 2025.3.0.35737 and all previous 2025.x versions, 2024.4.1.27687 and all previous 2024.x versions, 2023.3.0.23028 and all previous 2023.x versions, 14.0.7.33751 and all previous 14.x versions, 13.2.6.24111 and earlier
Timeline
- 2026-09-23: disclosed: CVE-2026-91805 disclosed
- 2026-09-23: patched: Fixed in Foxit PDF Reader 2026.2.1 and Foxit PDF Editor 2026.2.1/14.0.8