SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2026-57258

The PRC file header parsing logic trusts the constructed file structure description information, assumes that the underlying array contains elements and reads them, leading to out-of-bounds reads and application crashes.

MEDIUM 6.1EPSS 0.16%

Does this matter?

Lower severity and a low EPSS score (0.16%). Track it; it rarely justifies an emergency change on its own.

Description

The PRC file header parsing logic trusts the constructed file structure description information, assumes that the underlying array contains elements and reads them, leading to out-of-bounds reads and application crashes.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
EPSS
0.16% probability · 6th percentile
CISA KEV
Not listed
Weakness
CWE-125
Affected
foxit/pdf editor · foxit/pdf reader
Source
14984358-7092-470d-8f34-ade47a7658a2

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.