CVE-2026-3776: Null pointer dereference in Foxit PDF Editor/Reader when accessing stamp annotation
The application does not validate the presence of required appearance (AP) data before accessing stamp annotation resources. When a PDF contains a stamp annotation missing its AP entry, the code continues to dereference the associated object without a prior null or validity check, which allows a crafted document to trigger a null pointer dereference and crash the application, resulting in denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3776?
CVE-2026-3776 has been classified with moderate severity due to the potential for denial of service through null pointer dereference.
How do I fix CVE-2026-3776?
To fix CVE-2026-3776, update to the latest version of Foxit PDF Editor or Foxit PDF Reader which address this vulnerability.
Which applications are affected by CVE-2026-3776?
CVE-2026-3776 affects Foxit PDF Editor and Foxit PDF Reader.
What attack vectors are associated with CVE-2026-3776?
CVE-2026-3776 can be exploited through specially crafted PDF files containing stamp annotations without proper AP data.
What are the potential impacts of exploiting CVE-2026-3776?
Exploiting CVE-2026-3776 may lead to application crashes or unexpected behavior, resulting in denial of service.