CVE-2026-57257 Details
Description
During the PRC parsing stage, there is a lack of boundary verification for the PRC entity index, which leads to an out-of-bounds read of the entity array. As a result, the application crashes.
A vulnerability exists in Foxit PDF Reader and Foxit PDF Editor for Windows and Mac, all prior versions through 2026.1.1, 14.0.4, and several different 2025.x, 2024.x, and 2023.x versions. During the PRC parsing stage, insufficient boundary verification of the PRC entity index leads to an out-of-bounds read of the entity array, causing the application to crash. This vulnerability could be exploited when the application processes certain PDFs with abnormal page trees, image objects, or color spaces, after JavaScript execution has altered the document.
Users can update to Foxit PDF Reader or Foxit PDF Editor version 2026.1.2. For Foxit PDF Editor for Mac, version 2026.1.2/14.0.5 is available. Foxit PDF Editor 13.2.5 also addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.foxit.com/support/security-bulletins.html | Foxit | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | Foxit |
Affected Products
| Product | Versions |
|---|---|
| foxit pdf editor | <= 13.2.4.24048 >= 14.0.0.33046, <= 14.0.4.33508 >= 2023.1.0.15510, <= 2023.3.0.23028 >= 2024.1.0.23997, <= 2024.4.1.27687 >= 2025.1.0.27937, <= 2025.3.0.35737 >= 2026.1.0.36452, <= 2026.1.1.36485 <= 13.2.3.63444 >= 14.0.0.68868, <= 14.0.3.69295 >= 2023.1.0.55583, <= 2023.3.0.63083 >= 2024.1.0.63682, <= 2024.4.1.66479 >= 2025.1.0.66692, <= 2025.3.0.69570 >= 2026.1.0.70169, <= 2026.1.1.70276 |
CPE
Remediation
| |
| foxit pdf reader | <= 2026.1.1.36485 <= 2026.1.1.70276 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
| apple macos | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | Initial Analysis | [email protected] |
| Jul 8, 2026 | CVE Modified | CISA-ADP |
| Jul 8, 2026 | New CVE Received | Foxit |