2026-04-27 11:0CVE-2026-5938Foxit
PUBLISHED5.2CWE-691

Foxit PDF Editor/Reader Infinite Loop Denial-of-Service Vulnerability

Improper control flow management allows a crafted document action chain to cause modal dialog reentry on the main thread, resulting in UI freeze and denial of service.

Problem type

Affected products

Foxit Software Inc.

Foxit PDF Editor

Versions 2026.1 and earlier - AFFECTED

Versions 14.0.3 and earlier - AFFECTED

Versions 13.2.3 and earlier - AFFECTED

Foxit PDF Reader

Versions 2026.1 and earlier - AFFECTED

References

GitHub Security Advisories

GHSA-7r3x-9grv-cr95

Improper control flow management allows a crafted document action chain to cause modal dialog...

https://github.com/advisories/GHSA-7r3x-9grv-cr95

Improper control flow management allows a crafted document action chain to cause modal dialog reentry on the main thread, resulting in UI freeze and denial of service.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-5938
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-5938",
    "assignerOrgId": "14984358-7092-470d-8f34-ade47a7658a2",
    "assignerShortName": "Foxit",
    "dateUpdated": "2026-04-27T11:00:38.202Z",
    "dateReserved": "2026-04-09T03:42:07.680Z",
    "datePublished": "2026-04-27T11:00:38.202Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "14984358-7092-470d-8f34-ade47a7658a2",
        "shortName": "Foxit",
        "dateUpdated": "2026-04-27T11:00:38.202Z"
      },
      "title": "Foxit PDF Editor/Reader Infinite Loop Denial-of-Service Vulnerability",
      "descriptions": [
        {
          "lang": "en",
          "value": "Improper control flow management allows a crafted document action chain to cause modal dialog reentry on the main thread, resulting in UI freeze and denial of service.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "Improper control flow management allows a crafted document action chain to cause modal dialog reentry on the main thread, resulting in UI freeze and denial of service."
            }
          ]
        }
      ],
      "affected": [
        {
          "vendor": "Foxit Software Inc.",
          "product": "Foxit PDF Editor",
          "platforms": [
            "Windows"
          ],
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "Versions 2026.1 and earlier",
              "status": "affected"
            },
            {
              "version": "Versions 14.0.3 and earlier",
              "status": "affected"
            },
            {
              "version": "Versions 13.2.3 and earlier",
              "status": "affected"
            }
          ]
        },
        {
          "vendor": "Foxit Software Inc.",
          "product": "Foxit PDF Reader",
          "platforms": [
            "Windows"
          ],
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "Versions 2026.1 and earlier",
              "status": "affected"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "Insufficient Control Flow Management (CWE-691)",
              "cweId": "CWE-691",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://www.foxit.com/support/security-bulletins.html"
        }
      ],
      "impacts": [
        {
          "descriptions": [
            {
              "lang": "en",
              "value": "Denial of Service"
            }
          ]
        }
      ],
      "metrics": [
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ],
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "scope": "UNCHANGED",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "availabilityImpact": "HIGH",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM"
          }
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "CITIVD",
          "type": "finder"
        }
      ]
    }
  }
}