VYPR
High severity7.8NVD Advisory· Published Jul 8, 2026· Updated Jul 9, 2026

CVE-2026-13127

CVE-2026-13127

Description

The application opens the PDF file. JavaScript then rewrites the document to modify the page structure, resulting in the invalidation of the page objects. However, the thumbnails still use the invalid page objects, ultimately causing the application to crash.

Affected products

3
  • cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*range: <=13.2.4.24048
    • (no CPE)
  • cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:*
    Range: <=2026.1.1.36485

Patches

Vulnerability mechanics

References

1

News mentions

1