CVE-2026-57255: Security vulnerability in Foxit PDF Editor/Reader — OOB Read via NaN-Bypass Clamp
The application opens a PDF containing an abnormal color space whose attributes reference a valid but semantically malformed function. The function's output is not validated; when subsequently read, it produces an illegal pointer that accesses an out-of-bounds region, crashing the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57255?
The severity of CVE-2026-57255 is classified as medium with a CVSS score of 6.1.
How do I fix CVE-2026-57255?
To fix CVE-2026-57255, users should update to the latest version of Foxit PDF Editor or Foxit PDF Reader that addresses this vulnerability.
What type of vulnerability is CVE-2026-57255?
CVE-2026-57255 is an out-of-bounds read vulnerability caused by NaN-bypass clamp issues in Foxit PDF Editor and Reader.
What are the potential impacts of CVE-2026-57255?
The potential impacts of CVE-2026-57255 include application crashes and unintended access to memory regions.
Which software is affected by CVE-2026-57255?
CVE-2026-57255 affects Foxit PDF Editor and Foxit PDF Reader.