OCTOBER 4, 2026
Live Feed
Back to database
Case File

CVE-2026-91817

MEDIUM · CVSS 6.1 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-04

CyberRota Analysis

AI-Generated

A heap-based out-of-bounds read vulnerability in Foxit PDF Editor/Reader affects the handling of wide strings in embedded PDF JavaScript, leading to potential application crashes due to insufficient validation of string-deletion ranges. This flaw can be exploited through crafted PDF files, posing risks to users who process such documents. Organizations utilizing Foxit products, particularly those that handle untrusted PDFs, should prioritize patching this vulnerability to mitigate potential disruptions and security risks.

CVE
CVE-2026-91817
Severity
MEDIUM
CVSS
6.1
EPSS
0.11%
Java

Original NVD Description

A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of wide strings in embedded PDF JavaScript. Insufficient validation of string-deletion ranges can cause an integer underflow, resulting in an out-of-bounds read and application crash.

Related CVEs

Other vulnerabilities affecting the same vendor(s)