ZDI discloses two Foxit PDF Reader out-of-bounds read information disclosure vulnerabilities (CVE-2026-91807, CVE-2026-91808)
ZDI published two Foxit PDF Reader advisories for out-of-bounds read flaws in PDF and JPEG file parsing that can disclose sensitive information to a remote attacker; both are rated CVSS 3.3 and require user interaction.
On 2026-09-23, ZDI published two advisories covering out-of-bounds read vulnerabilities in Foxit PDF Reader. ZDI-26-736 (CVE-2026-91807) is an out-of-bounds read during PDF file parsing, and ZDI-26-737 (CVE-2026-91808) is an out-of-bounds read during JPEG file parsing. Both flaws can disclose sensitive information to a remote attacker, but only if a user opens a malicious file or visits a malicious page. ZDI assigned a CVSS score of 3.3 to each vulnerability, and neither advisory mentions exploitation in the wild.
- Two ZDI advisories published 2026-09-23: ZDI-26-736 and ZDI-26-737.
- ZDI-26-736 (CVE-2026-91807) is an out-of-bounds read in Foxit PDF Reader PDF file parsing.
- ZDI-26-737 (CVE-2026-91808) is an out-of-bounds read in Foxit PDF Reader JPEG file parsing.
- Both vulnerabilities can disclose sensitive information to a remote attacker.
- Both require user interaction: the user must visit a malicious page or open a malicious file.
- ZDI assigned CVSS 3.3 to both vulnerabilities.
- No exploitation in the wild is mentioned in either advisory.
Coverage timelineoldest first · each row is one article
- · 4d agoZDI-26-737: Foxit PDF Reader JPEG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
ZDI Published Advisories· 24
ZDI disclosed a Foxit PDF Reader JPEG parsing out-of-bounds read that can leak information (CVE-2026-91808).
- · 4d agoZDI-26-736: Foxit PDF Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
ZDI Published Advisories· 24
ZDI disclosed a Foxit PDF Reader out-of-bounds read that can disclose sensitive information.
Vulnerabilities in this storyAll →
- CVE-2026-918076.1—Heap Out-of-Bounds Read in Foxit PDF Editor/Reader Soft-Mask Parsingpublished · Foxit Software Foxit PDF Reader+1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
CVE-2026-91807+1 related CVE | Heap Out-of-Bounds Read in Foxit PDF Editor/Reader Soft-Mask Parsing CVE-2026-91807 is a heap-based out-of-bounds read (CWE-125) in Foxit PDF Editor and Foxit PDF Reader caused by insufficient validation of an image's soft-mask data attribute during PDF parsing, which can trigger an arithmetic underflow when computing read bounds. An attacker triggers the flaw by convincing a user to open a specially crafted PDF, since the vector is local with user interaction required and no privileges needed. Successful exploitation crashes the application (high availability impact) and may disclose a limited amount of process heap memory, consistent with the ZDI-26-736 characterization as an information disclosure vulnerability. Anyone opening untrusted PDFs with an affected Foxit PDF Editor or Reader build is exposed, though the advisory data does not enumerate specific version ranges. There is no known public proof of concept and no evidence of in-the-wild exploitation; the flaw is not on the CISA KEV list. |