CVE-2026-18772
Awaiting Analysis Awaiting Analysis - Queue

Improper Input Validation in Samsung rlottie

Vulnerability report for CVE-2026-18772, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-18

Assigner: Samsung TV & Appliance

Description

Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-18
Generated
2026-08-24
AI Q&A
2026-08-04
EPSS Evaluated
2026-08-23
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
samsung rlottie *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1325 The product manages a group of objects or resources and performs a separate memory allocation for each object, but it does not properly limit the total amount of memory that is consumed by all of the combined objects.
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper input validation in Samsung's rlottie library, allowing oversized serialized data payloads. It enables attackers to cause excessive resource consumption through deeply nested or oversized inputs, potentially leading to denial of service.

Detection Guidance

Detecting this vulnerability requires checking if your system uses a vulnerable version of Samsung's rlottie library. Inspect installed packages or binaries for rlottie and verify if they are below the patched version. No specific network commands are provided in the context.

Impact Analysis

The vulnerability could allow attackers to crash applications or systems by sending maliciously crafted data, disrupting normal operations. It may also lead to resource exhaustion, affecting performance and availability of services using rlottie.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it involves improper input validation leading to resource exhaustion rather than data exposure or privacy violations.

Mitigation Strategies

Update the rlottie library to the patched version that includes safety limits for nested inputs, render-node counts, and repeater copies. If updating is not possible, restrict input sources to trusted files and validate all serialized data payloads before processing.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18772. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart