
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-57257 is an out-of-bounds read vulnerability in Foxit PDF Reader and PDF Editor that occurs during PRC (Product Representation Compact) file parsing. Due to insufficient boundary verification for the PRC entity index, the application reads beyond the intended entity array bounds, resulting in an application crash. Affected products include Foxit PDF Reader (versions 2026.1.1 and earlier) and Foxit PDF Editor (versions 2026.1.1, 14.0.4, 13.2.4, and earlier across multiple release branches). The vulnerability was published on July 8, 2026, with a CVSS v3.1 base score of 6.1 (Medium) (GitHub Advisory, Foxit Security Bulletins).
The root cause is classified as CWE-125 (Out-of-bounds Read): during the PRC parsing stage, the application fails to validate that a PRC entity index falls within the bounds of the entity array before performing a read operation. An attacker can craft a malicious PRC file with an out-of-range entity index that, when parsed by the application, triggers a read past the end of the allocated buffer. Exploitation requires local access and user interaction — specifically, a victim must open the malicious file. The attack complexity is low, and no special privileges are required (GitHub Advisory, Foxit Security Bulletins).
Successful exploitation causes the Foxit PDF Reader or PDF Editor application to crash, resulting in a denial of service for the affected user. The CVSS scoring also indicates a low confidentiality impact, suggesting that the out-of-bounds read may expose limited amounts of memory content, though the primary consequence is availability loss. There is no integrity impact, and the scope is limited to the affected application without evidence of lateral movement potential (GitHub Advisory).
.prc extension) in user download directories, email attachments, or temporary folders.FoxitPDFReader.exe or FoxitPDFEditor.exe)..dmp) in the application's crash reporting directory.Foxit has released patched versions addressing this vulnerability. Users should update Foxit PDF Reader and PDF Editor to versions beyond 2026.1.1 (for the 2026 branch), beyond 14.0.4 (for the 14.x branch), and beyond 13.2.4 (for the 13.x branch) via the Foxit security bulletins page. As a workaround, users should avoid opening PRC files from untrusted or unknown sources, and administrators can restrict access to PRC file processing in managed environments (Foxit Security Bulletins, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."