CVE-2026-18597: Foxit Software Inc Foxit PDF Services API
High severity, CVSS 8.5. EPSS: 0.3% chance of exploitation in the next 30 days.
The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is restricted, an attacker could trigger an SSRF vulnerability by using URL redirection to bypass validation, leading to information disclosure.
Affected products
- Foxit Software Inc Foxit PDF Services API: before 2026-07-27 (fixed in 2026-07-27)
Published 2026-08-06. Last modified 2026-08-26.