CVE-2026-57256: Foxit Editor/Reader List Box Format Use-After-Free Vulnerability
When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and this operation is repeated after the form is reset. During this process, the application failed to adequately verify the validity of the form objects and their internal dictionary pointers, resulting in accessing internal members of invalid or improperly initialized fields. This led to an illegal pointer read, ultimately causing the application to crash.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57256?
The severity of CVE-2026-57256 is rated high with a CVSS score of 7.8.
How do I fix CVE-2026-57256?
To fix CVE-2026-57256, update to the latest version of Foxit PDF Editor or Foxit PDF Reader that addresses this vulnerability.
What are the affected software versions for CVE-2026-57256?
CVE-2026-57256 affects Foxit PDF Editor and Foxit PDF Reader.
What type of vulnerability is CVE-2026-57256?
CVE-2026-57256 is classified as a Use After Free vulnerability.
What impact does CVE-2026-57256 have on users?
CVE-2026-57256 can lead to arbitrary code execution which may compromise user data integrity and application stability.