CVE-2026-57250
published 2026-07-08CVE-2026-57250: When the application opens a PDF and JavaScript resets the form fields, the script re-enters the interface. The underlying native object is damaged, but the…
PriorityP338high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.12%
1.9th percentile
When the application opens a PDF and JavaScript resets the form fields, the script re-enters the interface. The underlying native object is damaged, but the application does not perform validation. The function call on the damaged object leads to the application crashing.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| foxit | pdf_editor | <= 13.2.4.24048 | — |
| foxit | pdf_editor | <= 13.2.3.63444 | — |
| foxit | pdf_editor | 14.0.0.33046 – 14.0.4.33508 | — |
| foxit | pdf_editor | 14.0.0.68868 – 14.0.3.69295 | — |
| foxit | pdf_editor | 2023.1.0.15510 – 2023.3.0.23028 | — |
| foxit | pdf_editor | 2023.1.0.55583 – 2023.3.0.63083 | — |
| foxit | pdf_editor | 2024.1.0.23997 – 2024.4.1.27687 | — |
| foxit | pdf_editor | 2024.1.0.63682 – 2024.4.1.66479 | — |
| foxit | pdf_editor | 2025.1.0.27937 – 2025.3.0.35737 | — |
| foxit | pdf_editor | 2025.1.0.66692 – 2025.3.0.69570 | — |
| foxit | pdf_editor | 2026.1.0.36452 – 2026.1.1.36485 | — |
| foxit | pdf_editor | 2026.1.0.70169 – 2026.1.1.70276 | — |
| foxit | pdf_reader | <= 2026.1.1.36485 | — |
| foxit | pdf_reader | <= 2026.1.1.70276 | — |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_reader | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Foxit PDF Editor/PDF Reader Form Field Reset denial of service (WID-SEC-2026-2241)
vuldb·2026-07-09·CVSS 7.8
CVE-2026-57250 [HIGH] Foxit PDF Editor/PDF Reader Form Field Reset denial of service (WID-SEC-2026-2241)
A vulnerability identified as problematic has been detected in Foxit PDF Editor and PDF Reader. Affected by this vulnerability is an unknown functionality of the component Form Field Reset Handler. The manipulation leads to denial of service.
This vulnerability is referenced as CVE-2026-57250. The attack can only be performed from a local environment. No exploit is available.
GHSA
When the application opens a PDF and JavaScript resets the form fields, the script re-enters the interface.
ghsa_unreviewed·2026-07-08
CVE-2026-57250 [HIGH] CWE-416 When the application opens a PDF and JavaScript resets the form fields, the script re-enters the interface.
When the application opens a PDF and JavaScript resets the form fields, the script re-enters the interface. The underlying native object is damaged, but the application does not perform validation. The function call on the damaged object leads to the application crashing.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-08
Published