CVE-2026-19587
Awaiting Analysis Awaiting Analysis - Queue

Uncontrolled Resource Consumption in Samsung rlottie

Vulnerability report for CVE-2026-19587, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-18

Assigner: Samsung TV & Appliance

Description

Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-18
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-31
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
samsung rlottie *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an uncontrolled resource consumption issue in Samsung's rlottie library. It allows excessive allocation due to repeaters in Lottie animations multiplying shapes up to 10,000 copies, each with up to 1,024 points. This can cause extremely high render costs per frame, leading to system resource exhaustion.

Detection Guidance

This vulnerability is specific to the rlottie library and relates to excessive resource consumption during Lottie animation rendering. Detection involves checking for unusually high CPU or memory usage when processing Lottie animations, particularly those with repeaters or complex shapes. Monitor for processes consuming excessive resources during animation playback.

Impact Analysis

This vulnerability can impact you by causing system slowdowns, crashes, or denial of service due to excessive CPU and memory usage during the rendering of malicious or complex Lottie animations. Normal animations remain unaffected.

Compliance Impact

The vulnerability does not directly impact compliance with GDPR or HIPAA. It primarily causes system resource exhaustion due to excessive render workloads in Lottie animations, which could lead to denial-of-service conditions. Compliance implications would depend on how the affected system is used in a regulated environment, but the vulnerability itself is not a direct violation of these standards.

Mitigation Strategies

Update the rlottie library to the patched version that introduces a shared budget of 15,000 weighted points to prevent excessive render workloads from repeaters in Lottie animations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19587. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart