CVE-2026-5936 Details
Description
An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations. This behavior may be exploited to probe internal network services, access otherwise unreachable endpoints (e.g., cloud metadata services), or bypass network access controls, potentially leading to sensitive information disclosure and further compromise of the internal environment.
A server-side request forgery (SSRF) vulnerability has been identified in multiple Foxit products, including Foxit PDF Services API, Foxit PDF Reader, and Foxit PDF Editor. This vulnerability allows attackers to control HTTP requests initiated by the server, directing them to arbitrary destinations. Exploitation of this vulnerability could lead to probing internal network services, accessing otherwise unreachable endpoints such as cloud metadata services, or bypassing network access controls, potentially resulting in the disclosure of sensitive information and further compromise of the internal environment.
This vulnerability has been addressed in Foxit PDF Services API, Foxit PDF Reader 2026.1, and Foxit PDF Editor 2026.1. Users can update to the latest version through the Foxit Update mechanism or by downloading the updated version from the Foxit website. For Foxit PDF Editor for Mac, the latest version can also be downloaded from the Foxit website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.foxit.com/support/security-bulletins.html | Foxit | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | Foxit |
Affected Products
| Product | Versions |
|---|---|
| foxit pdf services api | < 2026-04-07 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 7, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | Foxit |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 13, 2026 | New CVE Received | Foxit |