CVE-2026-91807: Foxit PDF Editor/Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published Sep 23, 2026
·Updated
A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed image soft-mask data. Insufficient validation of the soft-mask data attribute during image parsing may cause an arithmetic underflow, resulting in an out-of-bounds read and application crash.
Affected Software
1 affected component
Foxit PDF Editor/Reader
Event History
Sep 23, 2026
CVE Published
via MITRE·07:50 AM
Data Sourced
via MITRE·07:50 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What must an attacker do to trigger this issue?
An attacker must persuade a user to open or process a specially crafted PDF containing malformed image soft-mask data. The vulnerability is triggered during PDF image parsing.
2
What are the likely impacts of successful exploitation?
The reported effects are an out-of-bounds read that may disclose information and cause the Foxit application to crash. The provided severity vector indicates local attack vector, no required privileges, and user interaction is required.