VYPR
High severity7.8NVD Advisory· Published Jul 8, 2026· Updated Jul 9, 2026

CVE-2026-13129

CVE-2026-13129

Description

When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in the program holding an invalid form object when accessing the field property path. Eventually, the application crashes due to reading an invalid pointer.

Affected products

3
  • cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*range: <=13.2.4.24048
    • (no CPE)
  • cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:*
    Range: <=2026.1.1.36485

Patches

Vulnerability mechanics

References

1

News mentions

1