Tracker / CVE-2026-57256
CVE-2026-57256
High 7.8
When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and this operation is repeated after the form is reset. During this process, the application failed to adequately verify the validity of the form objects and their internal dictionary pointers, resulting in accessing internal members of invalid or improperly initialized fields. This led to an illegal pointer read, ultimately causing the application to crash.
Affected products and versions
| foxit | pdf_editor · … → 13.2.4.24048 |
|---|---|
| foxit | pdf_editor · 14.0.0.33046 → 14.0.4.33508 |
| foxit | pdf_editor · 2023.1.0.15510 → 2023.3.0.23028 |
| foxit | pdf_editor · 2024.1.0.23997 → 2024.4.1.27687 |
| foxit | pdf_editor · 2025.1.0.27937 → 2025.3.0.35737 |
| foxit | pdf_editor · 2026.1.0.36452 → 2026.1.1.36485 |
| foxit | pdf_reader · … → 2026.1.1.36485 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.