CVE-2026-18597: Blind SSRF on Foxit PDF Services API
Published Aug 6, 2026
·Updated
The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is restricted, an attacker could trigger an SSRF vulnerability by using URL redirection to bypass validation, leading to information disclosure.
Affected Software
1 affected component
Foxit Foxit PDF Services API
Event History
Aug 6, 2026
CVE Published
via MITRE·07:37 AM
Data Sourced
via MITRE·07:37 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-18597?
CVE-2026-18597 has a severity rating of 8.5, indicating a high level of risk.
2
How do I fix CVE-2026-18597?
To address CVE-2026-18597, ensure you apply the latest patches or updates provided by Foxit for the PDF Services API.
3
What is the nature of the vulnerability in CVE-2026-18597?
CVE-2026-18597 is a blind Server Side Request Forgery (SSRF) vulnerability that may lead to information disclosure.
4
What impact can CVE-2026-18597 have on my system?
Exploitation of CVE-2026-18597 can lead to the unauthorized disclosure of sensitive information from internal resources.
5
Which software is affected by CVE-2026-18597?
CVE-2026-18597 affects the Foxit PDF Services API software.