CVE-2026-57258 Details
Description
The PRC file header parsing logic trusts the constructed file structure description information, assumes that the underlying array contains elements and reads them, leading to out-of-bounds reads and application crashes.
A vulnerability allowing out-of-bounds reads and application crashes has been identified in Foxit PDF Reader and Foxit PDF Editor. This issue arises from the PRC file header parsing logic, which improperly trusts the constructed file structure description. The vulnerability is present in several versions of Foxit PDF Reader and Foxit PDF Editor on Windows and macOS. When certain PDFs with abnormal PRC streams or Unity 3D objects are opened, the application fails to validate the data properly, leading to access violations that could be exploited to disclose information or execute arbitrary code.
Users can update to Foxit PDF Reader 2026.1.2 or Foxit PDF Editor 2026.1.2/14.0.5. Instructions for updating are available on the Foxit website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.foxit.com/support/security-bulletins.html | Foxit | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | Foxit |
Affected Products
| Product | Versions |
|---|---|
| foxit pdf editor | <= 13.2.4.24048 >= 14.0.0.33046, <= 14.0.4.33508 >= 2023.1.0.15510, <= 2023.3.0.23028 >= 2024.1.0.23997, <= 2024.4.1.27687 >= 2025.1.0.27937, <= 2025.3.0.35737 >= 2026.1.0.36452, <= 2026.1.1.36485 <= 13.2.3.63444 >= 14.0.0.33046, <= 14.0.3.69295 >= 2023.1.0.55583, <= 2023.3.0.63083 >= 2024.1.0.63682, <= 2024.4.1.66479 >= 2025.1.0.66692, <= 2025.3.0.69570 >= 2026.1.0.70169, <= 2026.1.1.70276 |
CPE
Remediation
| |
| foxit pdf reader | <= 2026.1.1.36485 <= 2026.1.1.70276 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
| apple macos | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | Initial Analysis | [email protected] |
| Jul 8, 2026 | CVE Modified | CISA-ADP |
| Jul 8, 2026 | New CVE Received | Foxit |