Junglewise Threat Intelligence

CVE-2026-91818: Foxit PDF Editor use-after-free in JavaScript annotation handling

CVE-2026-91818 · Severity: high · CVSS 7.8 · Published 2026-09-23

Technologies: Foxit PDF Reader, Foxit PDF Editor. Vendors: Foxit.

Executive brief

Foxit PDF Editor and Reader contain a use-after-free vulnerability in their JavaScript engine when processing PDF annotations. An attacker who crafts a malicious PDF with reentrant page-event code can trigger an application crash. While this does not enable code execution, it allows denial of service against users opening untrusted PDF files.

Technical details

The vulnerability occurs in Foxit's JavaScript handling during annotation enumeration, where reentrant page-event processing may release the underlying page object while it is still in use. The use-after-free leads to memory corruption and application crash. Exploitation requires user interaction (opening a crafted PDF) and does not require network or local privileges; a patch is available in versions 2026.2.1, 2025.3.0.35737+, 2024.4.1.27687+, 2023.3.0.23028+, 14.0.8+, and 13.2.6.24111+.

Affected products

  • Foxit PDF Editor 2026.2.0.39747 and earlier, 2025.x through 2025.3.0.35736, 2024.x through 2024.4.1.27686, 2023.x through 2023.3.0.23027, 14.x through 14.0.7.33751, 13.2.6.24111 and earlier
  • Foxit PDF Reader 2026.2.0.39747 and earlier

Timeline

  • 2026-09-23: disclosed: CVE-2026-91818 publicly disclosed
  • 2026-09-23: patched: Fixed in PDF Reader 2026.2.1, PDF Editor 2026.2.1/14.0.8 and later versions

References

Related threats