Junglewise Threat Intelligence

CVE-2026-91807: Foxit PDF Reader heap-based out-of-bounds read in image soft-mask parsing

CVE-2026-91807 · Severity: medium · CVSS 6.1 · Published 2026-09-23

Technologies: Foxit PDF Reader, Foxit PDF Editor. Vendors: Foxit.

Executive brief

Foxit PDF Reader and Editor are widely-used applications for viewing and editing PDF documents in business environments. A flaw in how they process malformed image data can cause the application to crash by reading memory beyond allocated boundaries, disrupting user work but not leading to data theft or system compromise.

Technical details

A heap-based out-of-bounds read exists in the image soft-mask parsing logic due to insufficient validation of soft-mask data attributes. Arithmetic underflow during image parsing causes the application to read beyond heap boundaries, resulting in a denial of service via application crash. The vulnerability requires user interaction (opening a malicious PDF) and is triggered at parse time with no authentication needed.

Affected products

  • Foxit PDF Reader 2026.2.0.39747 and earlier
  • Foxit PDF Editor 2026.2.0.39747 and all previous 2026.x versions, 2025.3.0.35737 and all previous 2025.x versions, 2024.4.1.27687 and all previous 2024.x versions, 2023.3.0.23028 and all previous 2023.x versions, 14.0.7.33751 and all previous 14.x versions, 13.2.6.24111 and earlier

Timeline

  • 2026-09-23: disclosed
  • 2026-09-23: patched: Foxit PDF Reader 2026.2.1 and Foxit PDF Editor 2026.2.1/14.0.8 released

References

Related threats