CVE-2026-3778: Foxit PDF Editor

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

The application does not detect or guard against cyclic PDF object references while handling JavaScript in PDF. When pages and annotations are crafted that reference each other in a loop, passing the document to APIs (e.g., SOAP) that perform deep traversal can cause uncontrolled recursion, stack exhaustion, and application crashes.

Affected products

  • Foxit PDF Editor: up to and including 13.2.2.24014; from 14.0.0.33046, up to and including 14.0.2.33402; from 2023.1.0.15510, up to and including 2023.3.0.23028; from 2024.1.0.23997, up to and including 2024.4.1.27687; from 2025.1.0.27937, up to and including 2025.3.0.35737; up to and including 13.2.2.63349; …
  • Foxit PDF Reader: up to and including 2025.3.0.35737; up to and including 2025.3.0.69570

Published 2026-04-01. Last modified 2026-06-17.