Ad

CVE-2026-5936

HIGH CVSS 3.1: 8.5 EPSS 0.03%
Updated Apr 13, 2026
Foxit Software Inc.
Parameter Value
CVSS 8.5 (HIGH)
Type CWE-918 (Server-Side Request Forgery (SSRF))
Vendor Foxit Software Inc.
Public PoC No

An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations. This behavior may be exploited to probe internal network services, access otherwise unreachable endpoints (e.g., cloud metadata services), or bypass network access controls, potentially leading to sensitive information disclosure and further compromise of the internal environment.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products

foxit software inc.:foxit pdf services api