CVE-2026-19517
Received Received - Intake

Excessive Allocation in rlottie Due to Improper Input Validation

Vulnerability report for CVE-2026-19517, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: Samsung TV & Appliance

Description

Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerability in Samsung Open Source rlottie allows Excessive Allocation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
samsung rlottie to 3.0.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
CWE-1284 The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper input validation and resource allocation in Samsung's rlottie library. It allows excessive resource consumption due to lack of limits or throttling when processing certain inputs, potentially leading to system instability or crashes.

Detection Guidance

To detect this vulnerability, monitor for excessive resource consumption by rlottie processes. Check for unusually high CPU or memory usage during media processing. Inspect logs for errors related to deep nesting or oversized inputs in animations. Validate if the installed rlottie version lacks the safety limits mentioned in the patch.

Impact Analysis

An attacker could exploit this to cause denial-of-service by consuming excessive system resources through specially crafted inputs, leading to application crashes or degraded performance on affected systems.

Compliance Impact

The vulnerability involves excessive resource allocation due to improper input validation, which could lead to denial-of-service conditions. This may impact compliance with standards like GDPR or HIPAA by disrupting system availability, potentially affecting data processing or service delivery. However, specific compliance impacts are not detailed in the provided context.

Mitigation Strategies

Update to the latest version of Samsung Open Source rlottie that includes safety limits for resource consumption, such as capping nesting depth and render-node count. Monitor for excessive resource usage in applications using rlottie.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19517. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart