Junglewise Threat Intelligence

CVE-2026-91808: Foxit PDF Editor heap out-of-bounds read in image handling

CVE-2026-91808 · Severity: medium · CVSS 6.1 · Published 2026-09-23

Technologies: Foxit PDF Reader, Foxit PDF Editor. Vendors: Foxit.

Executive brief

Foxit PDF Editor and Reader are tools used to create, edit, and view PDF documents. A flaw in how these applications process PDF image objects with incorrect compression metadata can cause the application to crash when opening a malicious PDF. An attacker could exploit this to disrupt users' work or potentially trigger further exploitation.

Technical details

A heap-based out-of-bounds read vulnerability exists in the image decoding logic when handling PDF image objects with inconsistent compression metadata. The vulnerability stems from insufficient validation during image decoding, leading to an undersized buffer allocation and an out-of-bounds read during rendering. Exploitation requires user interaction (opening a crafted PDF) and results in an application crash (denial of service).

Affected products

  • Foxit PDF Reader 2026.2.0.39747 and earlier
  • Foxit PDF Editor 2026.2.0.39747 and all previous 2026.x, 2025.3.0.35737 and all previous 2025.x, 2024.4.1.27687 and all previous 2024.x, 2023.3.0.23028 and all previous 2023.x, 14.0.7.33751 and all previous 14.x, 13.2.6.24111 and earlier

Timeline

  • 2026-09-23: disclosed: Security bulletin published
  • 2026-09-23: patched: Fixed in Foxit PDF Reader 2026.2.1 and Foxit PDF Editor 2026.2.1/14.0.8

References

Related threats