CVE-2026-57252
published 2026-07-08CVE-2026-57252: When the application opens a PDF file, during the process of JavaScript deleting pages and removing attachment annotations, it will cause the attachment panel…
PriorityP335high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.12%
1.9th percentile
When the application opens a PDF file, during the process of JavaScript deleting pages and removing attachment annotations, it will cause the attachment panel to continue accessing invalid pointers, eventually leading to the application crashing.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| foxit | pdf_editor | <= 13.2.4.24048 | — |
| foxit | pdf_editor | 14.0.0.33046 – 14.0.4.33508 | — |
| foxit | pdf_editor | 2023.1.0.15510 – 2023.3.0.23028 | — |
| foxit | pdf_editor | 2024.1.0.23997 – 2024.4.1.27687 | — |
| foxit | pdf_editor | 2025.1.0.27937 – 2025.3.0.35737 | — |
| foxit | pdf_editor | 2026.1.0.36452 – 2026.1.1.36485 | — |
| foxit | pdf_reader | <= 2026.1.1.36485 | — |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_reader | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Foxit PDF Editor/PDF Reader PDF File denial of service (WID-SEC-2026-2241)
vuldb·2026-07-09·CVSS 7.8
CVE-2026-57252 [HIGH] Foxit PDF Editor/PDF Reader PDF File denial of service (WID-SEC-2026-2241)
A vulnerability labeled as problematic has been found in Foxit PDF Editor and PDF Reader. Affected by this issue is some unknown functionality of the component PDF File Handler. The manipulation results in denial of service.
This vulnerability is identified as CVE-2026-57252. The attack can be executed remotely. There is not any exploit available.
GHSA
When the application opens a PDF file, during the process of JavaScript deleting pages and removing attachment annotations, it will cause the attachment panel to continue accessing invalid pointers, e
ghsa_unreviewed·2026-07-08
CVE-2026-57252 [HIGH] CWE-416 When the application opens a PDF file, during the process of JavaScript deleting pages and removing attachment annotations, it will cause the attachment panel to continue accessing invalid pointers, e
When the application opens a PDF file, during the process of JavaScript deleting pages and removing attachment annotations, it will cause the attachment panel to continue accessing invalid pointers, eventually leading to the application crashing.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-08
Published