CVE-2026-57250 Details
Description
When the application opens a PDF and JavaScript resets the form fields, the script re-enters the interface. The underlying native object is damaged, but the application does not perform validation. The function call on the damaged object leads to the application crashing.
A use-after-free vulnerability has been identified in Foxit PDF Reader and Foxit PDF Editor. This vulnerability occurs when the application processes PDFs containing specific JavaScript that resets form fields. The JavaScript execution can disrupt the normal functioning of the application by damaging underlying native objects. However, the application fails to validate these objects properly. As a result, the application may crash when a function is called on the compromised object. This vulnerability could be exploited to execute arbitrary code remotely.
Users can update to the latest versions of Foxit PDF Reader or Foxit PDF Editor. Instructions for updating are available on the Foxit website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.foxit.com/support/security-bulletins.html | Foxit | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | Foxit |
Affected Products
| Product | Versions |
|---|---|
| foxit pdf editor | <= 13.2.4.24048 >= 14.0.0.33046, <= 14.0.4.33508 >= 2023.1.0.15510, <= 2023.3.0.23028 >= 2024.1.0.23997, <= 2024.4.1.27687 >= 2025.1.0.27937, <= 2025.3.0.35737 >= 2026.1.0.36452, <= 2026.1.1.36485 <= 13.2.3.63444 >= 14.0.0.68868, <= 14.0.3.69295 >= 2023.1.0.55583, <= 2023.3.0.63083 >= 2024.1.0.63682, <= 2024.4.1.66479 >= 2025.1.0.66692, <= 2025.3.0.69570 >= 2026.1.0.70169, <= 2026.1.1.70276 |
CPE
Remediation
| |
| foxit pdf reader | <= 2026.1.1.36485 <= 2026.1.1.70276 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
| apple macos | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | Initial Analysis | [email protected] |
| Jul 8, 2026 | CVE Modified | CISA-ADP |
| Jul 8, 2026 | New CVE Received | Foxit |