CVE-2026-18597 PUBLISHED

Blind SSRF on Foxit PDF Services API

Assigner: Foxit
Reserved: 03.08.2026 Published: 06.08.2026 Updated: 06.08.2026

The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is restricted, an attacker could trigger an SSRF vulnerability by using URL redirection to bypass validation, leading to information disclosure.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
CVSS Score: 8.5

Product Status

Vendor Foxit Software Inc.
Product Foxit PDF Services API
Versions Default: unaffected
  • Version before 2026-07-27 is affected

Credits

  • mrfathoni finder

References

Problem Types

  • CWE-918: Server-Side Request Forgery (SSRF) CWE

Impacts

  • Information Disclosure