ZDI-26-737: Foxit PDF Reader JPEG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
ZDI disclosed a Foxit PDF Reader JPEG parsing out-of-bounds read that can leak information (CVE-2026-91808).
ZDI-26-737 is an out-of-bounds read in Foxit PDF Reader's JPEG file parsing that can disclose sensitive information to a remote attacker. The user must visit a malicious page or open a malicious file. ZDI assigned CVSS 3.3 and CVE-2026-91808, with no statement of active exploitation.
- JPEG parsing out-of-bounds read can disclose information.
- User interaction via a malicious page or file is required.
- ZDI assigns CVSS 3.3 and CVE-2026-91808.
- No exploitation in the wild is mentioned.
Vulnerabilities mentionedAll →
- CVE-2026-918086.1—Heap Out-of-Bounds Read in Foxit PDF Editor Reader Image Decodingpublished · Foxit PDF Editor Reader (Foxit PDF Reader)
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-91808 | Heap Out-of-Bounds Read in Foxit PDF Editor Reader Image Decoding CVE-2026-91808 is a heap-based out-of-bounds read (CWE-125) in Foxit PDF Editor Reader's handling of PDF image objects whose compression metadata is inconsistent, related to JPEG file parsing per ZDI advisory ZDI-26-737. When a crafted PDF is opened, insufficient validation during image decoding can allocate an undersized buffer, and reading beyond it during rendering crashes the application. An attacker gains a denial-of-service condition and potentially limited information disclosure (memory contents) via the out-of-bounds read. Exploitation requires convincing a user to open a malicious PDF, since the attack vector is local with user interaction required and no privileges needed. The flaw is not in the CISA KEV catalog and no public proof-of-concept is known, so there is no evidence of active exploitation. |
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-91808.
This source does not provide full text. Read it at zerodayinitiative.com.