CVE-2026-91808

A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor Reader’s handling of PDF image objects with inconsistent compression metadata. Insufficient validation during image decoding may result in an undersized buffer and an out-of-bounds read during rendering, causing an application crash.

  • Published Sep 23, 2026
  • CVSS 6.1 medium
  • 0.1% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2026-91808 at the National Vulnerability Database