Skip to content
CVSS 7.8 · HIGH

CVE-2026-5941

Parsing logic flaws cause non-signature data to be misidentified as valid signatures when processing malformed form field hierarchies, leading to invalid memory writes and program crashes during internal data structure construction.

View on NVD

Analysis

Foxit PDF Reader and Editor are vulnerable to memory corruption when processing specially crafted PDF documents with malformed form fields. Opening a malicious file could lead to application crashes or potentially allow an attacker to execute arbitrary code on the victim's machine.

Severity

Score: 7.8(HIGH)
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
AV: LOCAL
AC: LOW
PR: NONE
UI: REQUIRED
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-20NVD-CWE-noinfo

EPSS

Probability of exploitation (next 30 days): 0.0003 (0.0%)
Percentile: 8.3%
EPSS: 2026-05-06

Affects

foxit:pdf_editorfoxit:pdf_reader

Technical description

Parsing logic flaws cause non-signature data to be misidentified as valid signatures when processing malformed form field hierarchies, leading to invalid memory writes and program crashes during internal data structure construction.

Published: 4/27/2026, 12:16:24 PM
Last modified: 4/29/2026, 5:24:15 PM

References

HomeEventsBlogResourcesTeam