CVE-2026-3778 Details
Description
The application does not detect or guard against cyclic PDF object references while handling JavaScript in PDF. When pages and annotations are crafted that reference each other in a loop, passing the document to APIs (e.g., SOAP) that perform deep traversal can cause uncontrolled recursion, stack exhaustion, and application crashes.
A vulnerability allowing uncontrolled recursion has been identified in Foxit PDF Reader and Foxit PDF Editor. This issue arises when the application processes PDF files containing cyclic references between objects, particularly through JavaScript. The lack of detection for these cyclic references can lead to stack overflow, causing application crashes. The vulnerability is present in Foxit PDF Reader versions prior to 2026.1 and Foxit PDF Editor versions 2025.3.0.35737 and earlier, as well as several previous 2024.x, 2023.x, and 14.x versions.
Users can update to Foxit PDF Reader 2026.1 or Foxit PDF Editor 2026.1. Instructions for updating or downloading the latest versions are available on the Foxit website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.foxit.com/support/security-bulletins.html | Foxit | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-674 | Uncontrolled Recursion | Foxit |
Affected Products
| Product | Versions |
|---|---|
| foxit pdf editor | <= 13.2.2.24014 >= 14.0.0.33046, <= 14.0.2.33402 >= 2023.1.0.15510, <= 2023.3.0.23028 >= 2024.1.0.23997, <= 2024.4.1.27687 >= 2025.1.0.27937, <= 2025.3.0.35737 <= 13.2.2.63349 >= 14.0.0.68868, <= 14.0.2.69164 >= 2023.1.0.55583, <= 2023.3.0.63083 >= 2024.1.0.63682, <= 2024.4.1.66479 >= 2025.1.0.66692, <= 2025.3.0.69570 |
CPE
Remediation
| |
| foxit pdf reader | <= 2025.3.0.35737 <= 2025.3.0.69570 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
| apple macos | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Foxit |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 14, 2026 | Initial Analysis | [email protected] |
| Apr 1, 2026 | New CVE Received | Foxit |