ZeroHour

CVE-2026-3778

CVSS 3.1
5.5 medium
EPSS
<1%p1
Published
()
Modified
Description

The application does not detect or guard against cyclic PDF object references while handling JavaScript in PDF. When pages and annotations are crafted that reference each other in a loop, passing the document to APIs (e.g., SOAP) that perform deep traversal can cause uncontrolled recursion, stack exhaustion, and application crashes.

Vendors
foxit
Products
pdf editor, pdf reader
Weakness
CWE-674
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.