{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-18597","assignerOrgId":"14984358-7092-470d-8f34-ade47a7658a2","state":"PUBLISHED","assignerShortName":"Foxit","dateReserved":"2026-08-03T03:35:36.628Z","datePublished":"2026-08-06T07:37:34.679Z","dateUpdated":"2026-08-06T12:30:12.590Z"},"containers":{"cna":{"providerMetadata":{"orgId":"14984358-7092-470d-8f34-ade47a7658a2","shortName":"Foxit","dateUpdated":"2026-08-06T07:37:34.679Z"},"title":"Blind SSRF on Foxit PDF Services API","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-918","description":"CWE-918: Server-Side Request Forgery (SSRF)","type":"CWE"}]}],"impacts":[{"descriptions":[{"lang":"en","value":"Information Disclosure"}]}],"affected":[{"vendor":"Foxit Software Inc.","product":"Foxit PDF Services API","versions":[{"status":"affected","version":"before 2026-07-27"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is restricted, an attacker could trigger an SSRF vulnerability by using URL redirection to bypass validation, leading to information disclosure.","supportingMedia":[{"type":"text/html","base64":false,"value":"The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is restricted, an attacker could trigger an SSRF vulnerability by using URL redirection to bypass validation, leading to information disclosure."}]}],"references":[{"url":"https://www.foxit.com/support/security-bulletins.html"}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE","baseSeverity":"HIGH","baseScore":8.5,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"}}],"credits":[{"lang":"en","value":"mrfathoni","type":"finder"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 1.0.4"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-08-06T12:30:02.936471Z","id":"CVE-2026-18597","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-08-06T12:30:12.590Z"}}]}}