CVE-2026-5943
published 2026-04-27CVE-2026-5943: Document structural anomalies caused inconsistencies between page element relationships and internal index states. When scripts triggered document…
PriorityP336high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.18%
8.0th percentile
Document structural anomalies caused inconsistencies between page element relationships and internal index states. When scripts triggered document modifications, object reference validity was not properly maintained, leading to a crash when accessing an invalid pointer during page information queries.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| foxit | pdf_editor | < 13.2.4 | 13.2.4 |
| foxit | pdf_editor | >= 14.0.0 < 14.0.4 | 14.0.4 |
| foxit | pdf_editor | >= 2023.0.0 < 2026.1.1 | 2026.1.1 |
| foxit | pdf_reader | < 2026.1.1 | 2026.1.1 |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_reader | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Foxit PDF Editor/PDF Reader Page Information Query use after free (EUVD-2026-25829 / Nessus ID 310407)
vuldb·2026-04-27·CVSS 7.8
CVE-2026-5943 [HIGH] Foxit PDF Editor/PDF Reader Page Information Query use after free (EUVD-2026-25829 / Nessus ID 310407)
A vulnerability, which was classified as critical, was found in Foxit PDF Editor and PDF Reader. Affected by this vulnerability is an unknown functionality of the component Page Information Query Handler. Executing a manipulation can lead to use after free.
This vulnerability appears as CVE-2026-5943. The attack may be performed from remote. There is no available exploit.
GHSA
GHSA-8hgx-6h8v-fcg8: Document structural anomalies caused inconsistencies between page element relationships and internal index states
ghsa_unreviewed·2026-04-27
CVE-2026-5943 [HIGH] CWE-416 GHSA-8hgx-6h8v-fcg8: Document structural anomalies caused inconsistencies between page element relationships and internal index states
Document structural anomalies caused inconsistencies between page element relationships and internal index states. When scripts triggered document modifications, object reference validity was not properly maintained, leading to a crash when accessing an invalid pointer during page information queries.
No detection rules found.
No public exploits indexed.
2026-04-27
Published