CVE-2026-82797: Medium severity Samsung rLottie vulnerability
Published Aug 31, 2026
·Updated
Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Serialized Data with Nested Payloads.
This issue affects rlottie: before 8de0d9e6ca80ffef654965505981727b9fa06a51.
Affected Software
1 affected component
Samsung rLottie<8de0d9e6ca80ffef654965505981727b9fa06a51
Event History
Aug 31, 2026
CVE Published
via MITRE·11:28 AM
Data Sourced
via MITRE·11:28 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to do to trigger the denial of service?
An attacker must cause a user to process serialized data containing nested payloads. The CVSS vector indicates local access and user interaction are required, while no privileges are required.
2
Which rlottie versions are affected?
rlottie versions before commit 8de0d9e6ca80ffef654965505981727b9fa06a51 are affected.
3
What is the impact if exploitation succeeds?
The vulnerability can cause uncontrolled recursion and affect availability. The provided CVSS metrics indicate no confidentiality or integrity impact.