Junglewise Threat Intelligence

CVE-2026-91810: Foxit PDF Reader heap out-of-bounds read in image mask handling

CVE-2026-91810 · Severity: medium · CVSS 6.1 · Published 2026-09-23

Technologies: Foxit PDF Reader, Foxit PDF Editor. Vendors: Foxit.

Executive brief

Foxit PDF Reader and PDF Editor applications contain a heap-based memory vulnerability triggered by specially crafted PDF files with malformed image masks. An attacker can exploit this by sending a malicious PDF that causes the application to read memory outside its intended bounds, crashing the application or potentially disclosing sensitive data from memory.

Technical details

A heap-based out-of-bounds read vulnerability exists in the PDF rendering engine's image mask handling code. The vulnerability occurs due to inconsistent validation of image metadata, causing incorrect alpha-channel processing during PDF rendering that reads beyond allocated heap memory. This is triggered by opening a malicious PDF file and can result in information disclosure or denial of service.

Affected products

  • Foxit PDF Reader 2026.2.0.39747 and earlier
  • Foxit PDF Editor 2026.2.0.39747 and earlier (2026.x), 2025.3.0.35737 and earlier (2025.x), 2024.4.1.27687 and earlier (2024.x), 2023.3.0.23028 and earlier (2023.x), 14.0.7.33751 and earlier (14.x), 13.2.6.24111 and earlier (13.x)

Timeline

  • 2026-09-23: disclosed: CVE-2026-91810 publicly disclosed; patched versions released
  • 2026-09-23: patched: Foxit PDF Reader 2026.2.1 and PDF Editor 2026.2.1/14.0.8 released

References

Related threats