CVE-2026-3778
MEDIUMStack exhaustion caused by cyclic references in Foxit PDF Editor/Reader
Title source: cnaDescription
The application does not detect or guard against cyclic PDF object references while handling JavaScript in PDF. When pages and annotations are crafted that reference each other in a loop, passing the document to APIs (e.g., SOAP) that perform deep traversal can cause uncontrolled recursion, stack exhaustion, and application crashes.
References (1)
Scores
CVSS v3
6.2
EPSS
0.0001
EPSS Percentile
2.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-674
Status
published
Products (6)
foxit/pdf_editor
< 13.2.2.24014
foxit/pdf_reader
< 2025.3.0.35737
Foxit Software Inc./Foxit PDF Editor
Versions 13.2.2 and earlier
Foxit Software Inc./Foxit PDF Editor
Versions 14.0.2 and earlier
Foxit Software Inc./Foxit PDF Editor
Versions 2025.3 and earlier
Foxit Software Inc./Foxit PDF Reader
Versions 2025.3 and earlier
Published
Apr 01, 2026
Tracked Since
Apr 01, 2026