{"id":"CVE-2026-91808","title":"A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor Reader’s handling of PDF image objects with inconsistent compression metadata","summary":"A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor Reader’s handling of PDF image objects with inconsistent compression metadata. Insufficient validation during image decoding may result in an undersized buffer and …","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","cwe":["CWE-125"],"vendor":"Foxit Software Inc.","product":"Foxit PDF Editor","affected":["foxit_pdf_editor Versions 2026.2 and earlier","foxit_pdf_editor Versions 14.0.7 and earlier","foxit_pdf_editor Versions 13.2.6 and earlier","foxit_pdf_reader Versions 2026.2 and earlier"],"published":"2026-09-23","updated":"2026-09-23","sourceUpdated":"2026-09-23T08:17:12.930","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-91808","references":[{"url":"https://www.foxit.com/support/security-bulletins.html","label":"14984358-7092-470d-8f34-ade47a7658a2"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-23T08:20:37.593Z","slug":"CVE-2026-91808","body":"## Overview\n\nA heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor Reader’s handling of PDF image objects with inconsistent compression metadata. Insufficient validation during image decoding may result in an undersized buffer and an out-of-bounds read during rendering, causing an application crash.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}