
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5937 is a denial-of-service vulnerability in Foxit PDF Reader and Foxit PDF Editor caused by insufficient parameter verification during file processing. When a malformed file is opened, the application fails to handle a std::invalid_argument exception, causing the program to terminate. Affected products include Foxit PDF Reader (versions before 2026.1.1), Foxit PDF Editor (versions before 13.2.4, 14.0.0–14.0.3, and 2023.0.0–2026.1.0). The vulnerability was published on April 27, 2026, and carries a CVSS v3.1 base score of 5.5 (Medium) (GitHub Advisory, Foxit Security Bulletins).
The root cause is classified as CWE-248 (Uncaught Exception): the application performs insufficient validation of file parameters, allowing a specially crafted file to induce a format error that raises an unhandled std::invalid_argument C++ exception. The attack vector is local (AV:L), requiring no privileges but necessitating user interaction — specifically, a user must open or process the malicious file. No authentication or elevated privileges are required for the attacker to deliver the malicious file, but the victim must interact with it to trigger the crash (GitHub Advisory, Foxit Security Bulletins).
Successful exploitation results in an application crash (denial of service), with high availability impact and no confidentiality or integrity impact. The affected scope is limited to the Foxit PDF Reader or Editor process on the victim's local system; there is no evidence of lateral movement potential or data exposure risk. The vulnerability cannot be used to execute arbitrary code or access sensitive information (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.013–0.015%, placing it in the 3rd percentile for exploitation likelihood within the next 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins are available via Nessus (plugin 310407) and Qualys (plugin 387163) (Feedly).
std::invalid_argument exception that is not caught, and the process terminates abruptly, resulting in a denial of service (GitHub Advisory).std::invalid_argument).FoxitPDFReader.exe or FoxitPDFEditor.exe processes without user-initiated close action.Foxit has released patched versions addressing this vulnerability: Foxit PDF Reader 2026.1.1 and later, Foxit PDF Editor 13.2.4 and later (for the 13.x branch), 14.0.4 and later (for the 14.x branch), and 2026.1.1 and later (for the 2026.x branch). Users should update to the latest available version via the Foxit Security Bulletins page. As a temporary workaround, users should avoid opening PDF files from untrusted or unknown sources, and administrators should monitor application logs for crash events indicative of exploitation attempts (Foxit Security Bulletins, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."