CVE-2026-18772: Medium severity Samsung rLottie vulnerability
Published Aug 4, 2026
·Updated
Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion.
Affected Software
1 affected component
Samsung rLottie
Event History
Aug 4, 2026
CVE Published
via MITRE·08:22 AM
Data Sourced
via MITRE·08:22 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:19 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-18772?
CVE-2026-18772 has a medium severity rating of 5.5.
2
What type of vulnerability is CVE-2026-18772?
CVE-2026-18772 is categorized as an improper input validation vulnerability.
3
What is the impact of CVE-2026-18772?
CVE-2026-18772 allows oversized serialized data payloads, potentially affecting data integrity.
4
How do I fix CVE-2026-18772?
To mitigate CVE-2026-18772, ensure proper input validation is implemented to restrict data payload sizes.
5
Is CVE-2026-18772 exploitable remotely?
Yes, CVE-2026-18772 can be exploited remotely, as indicated by its attack vector.