Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion.
cve CVE-2026-18772 1 source, 1 claim · Watch
NVD writes:
Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion. the claim
Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion. the claim
- Severity
- MEDIUM NVD
- CVSS
- 6.5 NVD
- Vendor
- Samsung Open Source NVD
- Product
- rlottie NVD
- CWE
- CWE-1325 NVD
How far exploitation has got
- No public code known
- Proof of concept
- Proof of concept, verified
- A Metasploit module
- Exploited in the wild
- Used in ransomware campaigns
Timeline
| 2026-08-04 | first spoke of it: Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion. | NVD |
What it is to other things
| affects | samsung/rlottie NVD |
| made_by | samsung NVD |
In words only, so not counted until a person confirms one:
| made_by | samsung_open_sourceNVD says “Samsung Open Source” |
| affects | samsung_open_source/rlottieNVD says “Samsung Open Source · rlottie” |
Every value, with what each source said and its receipt
| Property | Source | Said | Means here | ||||
|---|---|---|---|---|---|---|---|
| Automatable automatable | NVD | no At least one of those steps needs a person. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "rlottie",
"vendor": "Samsung Open Source",
"versions": [
{
"status": "unaffected",
"version": "f487eff2f8086b84ae1c7faa0418abec909e874b"
}
]
}
],
"source": "PSIRT@samsung.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:samsung:rlottie:-:*:*:*:*:*:*:*",
"matchCriteriaId": "839F9D6A-5E2B-4FDF-9F6F-CB9D3ED281F0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion."
}
],
"id": "CVE-2026-18772",
"lastModified": "2026-09-23T15:59:32.730",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 3.6,
"source": "PSIRT@samsung.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-18772",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-04T13:16:08.111242Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-08-04T10:19:32.923",
"references": [
{
"source": "PSIRT@samsung.com",
"tags": [
"Patch"
],
"url": "https://github.com/Samsung/rlottie/pull/596"
}
],
"sourceIdentifier": "PSIRT@samsung.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-1325"
}
],
"source": "PSIRT@samsung.com",
"type": "Secondary"
}
]
}
} | — | ||||
| CVSS cvss | NVD | 6.5receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "rlottie",
"vendor": "Samsung Open Source",
"versions": [
{
"status": "unaffected",
"version": "f487eff2f8086b84ae1c7faa0418abec909e874b"
}
]
}
],
"source": "PSIRT@samsung.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:samsung:rlottie:-:*:*:*:*:*:*:*",
"matchCriteriaId": "839F9D6A-5E2B-4FDF-9F6F-CB9D3ED281F0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion."
}
],
"id": "CVE-2026-18772",
"lastModified": "2026-09-23T15:59:32.730",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 3.6,
"source": "PSIRT@samsung.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-18772",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-04T13:16:08.111242Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-08-04T10:19:32.923",
"references": [
{
"source": "PSIRT@samsung.com",
"tags": [
"Patch"
],
"url": "https://github.com/Samsung/rlottie/pull/596"
}
],
"sourceIdentifier": "PSIRT@samsung.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-1325"
}
],
"source": "PSIRT@samsung.com",
"type": "Secondary"
}
]
}
} | — | ||||
| CVSS vector cvss_vector | NVD | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:Hreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "rlottie",
"vendor": "Samsung Open Source",
"versions": [
{
"status": "unaffected",
"version": "f487eff2f8086b84ae1c7faa0418abec909e874b"
}
]
}
],
"source": "PSIRT@samsung.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:samsung:rlottie:-:*:*:*:*:*:*:*",
"matchCriteriaId": "839F9D6A-5E2B-4FDF-9F6F-CB9D3ED281F0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion."
}
],
"id": "CVE-2026-18772",
"lastModified": "2026-09-23T15:59:32.730",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 3.6,
"source": "PSIRT@samsung.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-18772",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-04T13:16:08.111242Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-08-04T10:19:32.923",
"references": [
{
"source": "PSIRT@samsung.com",
"tags": [
"Patch"
],
"url": "https://github.com/Samsung/rlottie/pull/596"
}
],
"sourceIdentifier": "PSIRT@samsung.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-1325"
}
],
"source": "PSIRT@samsung.com",
"type": "Secondary"
}
]
}
} | — | ||||
| CWE cwe | NVD | CWE-1325receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "rlottie",
"vendor": "Samsung Open Source",
"versions": [
{
"status": "unaffected",
"version": "f487eff2f8086b84ae1c7faa0418abec909e874b"
}
]
}
],
"source": "PSIRT@samsung.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:samsung:rlottie:-:*:*:*:*:*:*:*",
"matchCriteriaId": "839F9D6A-5E2B-4FDF-9F6F-CB9D3ED281F0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion."
}
],
"id": "CVE-2026-18772",
"lastModified": "2026-09-23T15:59:32.730",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 3.6,
"source": "PSIRT@samsung.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-18772",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-04T13:16:08.111242Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-08-04T10:19:32.923",
"references": [
{
"source": "PSIRT@samsung.com",
"tags": [
"Patch"
],
"url": "https://github.com/Samsung/rlottie/pull/596"
}
],
"sourceIdentifier": "PSIRT@samsung.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-1325"
}
],
"source": "PSIRT@samsung.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Exploitation exploitation | NVD | none No evidence of exploitation, and no public proof of concept. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "rlottie",
"vendor": "Samsung Open Source",
"versions": [
{
"status": "unaffected",
"version": "f487eff2f8086b84ae1c7faa0418abec909e874b"
}
]
}
],
"source": "PSIRT@samsung.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:samsung:rlottie:-:*:*:*:*:*:*:*",
"matchCriteriaId": "839F9D6A-5E2B-4FDF-9F6F-CB9D3ED281F0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion."
}
],
"id": "CVE-2026-18772",
"lastModified": "2026-09-23T15:59:32.730",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 3.6,
"source": "PSIRT@samsung.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-18772",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-04T13:16:08.111242Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-08-04T10:19:32.923",
"references": [
{
"source": "PSIRT@samsung.com",
"tags": [
"Patch"
],
"url": "https://github.com/Samsung/rlottie/pull/596"
}
],
"sourceIdentifier": "PSIRT@samsung.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-1325"
}
],
"source": "PSIRT@samsung.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Product product | NVD | rlottiereceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "rlottie",
"vendor": "Samsung Open Source",
"versions": [
{
"status": "unaffected",
"version": "f487eff2f8086b84ae1c7faa0418abec909e874b"
}
]
}
],
"source": "PSIRT@samsung.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:samsung:rlottie:-:*:*:*:*:*:*:*",
"matchCriteriaId": "839F9D6A-5E2B-4FDF-9F6F-CB9D3ED281F0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion."
}
],
"id": "CVE-2026-18772",
"lastModified": "2026-09-23T15:59:32.730",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 3.6,
"source": "PSIRT@samsung.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-18772",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-04T13:16:08.111242Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-08-04T10:19:32.923",
"references": [
{
"source": "PSIRT@samsung.com",
"tags": [
"Patch"
],
"url": "https://github.com/Samsung/rlottie/pull/596"
}
],
"sourceIdentifier": "PSIRT@samsung.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-1325"
}
],
"source": "PSIRT@samsung.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Severity severity | NVD | MEDIUM From 4.0 to 6.9. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "rlottie",
"vendor": "Samsung Open Source",
"versions": [
{
"status": "unaffected",
"version": "f487eff2f8086b84ae1c7faa0418abec909e874b"
}
]
}
],
"source": "PSIRT@samsung.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:samsung:rlottie:-:*:*:*:*:*:*:*",
"matchCriteriaId": "839F9D6A-5E2B-4FDF-9F6F-CB9D3ED281F0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion."
}
],
"id": "CVE-2026-18772",
"lastModified": "2026-09-23T15:59:32.730",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 3.6,
"source": "PSIRT@samsung.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-18772",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-04T13:16:08.111242Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-08-04T10:19:32.923",
"references": [
{
"source": "PSIRT@samsung.com",
"tags": [
"Patch"
],
"url": "https://github.com/Samsung/rlottie/pull/596"
}
],
"sourceIdentifier": "PSIRT@samsung.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-1325"
}
],
"source": "PSIRT@samsung.com",
"type": "Secondary"
}
]
}
} | medium | ||||
| Status status | NVD | Analyzedreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "rlottie",
"vendor": "Samsung Open Source",
"versions": [
{
"status": "unaffected",
"version": "f487eff2f8086b84ae1c7faa0418abec909e874b"
}
]
}
],
"source": "PSIRT@samsung.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:samsung:rlottie:-:*:*:*:*:*:*:*",
"matchCriteriaId": "839F9D6A-5E2B-4FDF-9F6F-CB9D3ED281F0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion."
}
],
"id": "CVE-2026-18772",
"lastModified": "2026-09-23T15:59:32.730",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 3.6,
"source": "PSIRT@samsung.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-18772",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-04T13:16:08.111242Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-08-04T10:19:32.923",
"references": [
{
"source": "PSIRT@samsung.com",
"tags": [
"Patch"
],
"url": "https://github.com/Samsung/rlottie/pull/596"
}
],
"sourceIdentifier": "PSIRT@samsung.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-1325"
}
],
"source": "PSIRT@samsung.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Technical impact technical_impact | NVD | partial The attacker gains limited control, or limited information. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "rlottie",
"vendor": "Samsung Open Source",
"versions": [
{
"status": "unaffected",
"version": "f487eff2f8086b84ae1c7faa0418abec909e874b"
}
]
}
],
"source": "PSIRT@samsung.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:samsung:rlottie:-:*:*:*:*:*:*:*",
"matchCriteriaId": "839F9D6A-5E2B-4FDF-9F6F-CB9D3ED281F0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion."
}
],
"id": "CVE-2026-18772",
"lastModified": "2026-09-23T15:59:32.730",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 3.6,
"source": "PSIRT@samsung.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-18772",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-04T13:16:08.111242Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-08-04T10:19:32.923",
"references": [
{
"source": "PSIRT@samsung.com",
"tags": [
"Patch"
],
"url": "https://github.com/Samsung/rlottie/pull/596"
}
],
"sourceIdentifier": "PSIRT@samsung.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-1325"
}
],
"source": "PSIRT@samsung.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Vendor vendor | NVD | Samsung Open Sourcereceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "rlottie",
"vendor": "Samsung Open Source",
"versions": [
{
"status": "unaffected",
"version": "f487eff2f8086b84ae1c7faa0418abec909e874b"
}
]
}
],
"source": "PSIRT@samsung.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:samsung:rlottie:-:*:*:*:*:*:*:*",
"matchCriteriaId": "839F9D6A-5E2B-4FDF-9F6F-CB9D3ED281F0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion."
}
],
"id": "CVE-2026-18772",
"lastModified": "2026-09-23T15:59:32.730",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 3.6,
"source": "PSIRT@samsung.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-18772",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-04T13:16:08.111242Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-08-04T10:19:32.923",
"references": [
{
"source": "PSIRT@samsung.com",
"tags": [
"Patch"
],
"url": "https://github.com/Samsung/rlottie/pull/596"
}
],
"sourceIdentifier": "PSIRT@samsung.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-1325"
}
],
"source": "PSIRT@samsung.com",
"type": "Secondary"
}
]
}
} | — |
Every claim, by kind
vulnerability
| Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion. zetlyn/cve-nvd · 2026-08-04 | automatable no cvss 6.5 cvss_vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H cwe CWE-1325 exploitation none product rlottie severity MEDIUM status Analyzed technical_impact partial vendor Samsung Open Source | source |