CVE-2026-5937 Details
Description
Insufficient parameter verification leads to the occurrence of format errors in files, which will trigger an unhandled "std::invalid_argument" exception, ultimately causing the program to terminate.
A vulnerability exists in Foxit PDF Reader and Foxit PDF Editor for Windows, specifically in versions prior to 2026.1.1, 2025.3.0.35737, 2024.4.1.27687, 2023.3.0.23028, 14.0.3.335002, and 13.2.3.24041. This vulnerability is caused by insufficient parameter validation, which leads to format errors in files. These errors trigger an unhandled 'std::invalid_argument' exception, causing the program to crash. Additionally, improper control flow management can allow a crafted document action chain to disrupt the application's main thread, creating further stability issues.
Users can update to Foxit PDF Reader 2026.1.1 or Foxit PDF Editor 2026.1.1/14.0.4. Instructions for updating are available on the Foxit website. For Foxit PDF Editor versions 13.2.4, 14.0.3, and in the Mac versions of Foxit PDF Editor and Foxit PDF Reader, the latest versions can also be downloaded from the Foxit website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.foxit.com/support/security-bulletins.html | Foxit | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-248 | Uncaught Exception | Foxit |
Affected Products
| Product | Versions |
|---|---|
| foxit pdf editor | < 13.2.4 >= 14.0.0, < 14.0.4 >= 2023.0.0, < 2026.1.1 |
CPE
Remediation
| |
| foxit pdf reader | < 2026.1.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Foxit |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Initial Analysis | [email protected] |
| Apr 27, 2026 | New CVE Received | Foxit |