CVE-2026-91826: Buffer Overflow
Published Sep 15, 2026
·Updated
Stack-based buffer overflow vulnerability in Samsung Opensource rLottie allows attackers to overflow buffers, leading to memory corruption when rendering crafted vector animations.
This issue affects rLottie: 480a2ad0c5d2e45458c545b8213279e9e8b71e39.
Affected Software
1 affected component
rLottie=480a2ad0c5d2e45458c545b8213279e9e8b71e39
Event History
Sep 15, 2026
CVE Published
via MITRE·08:49 AM
Data Sourced
via MITRE·08:49 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What must an attacker do to trigger this issue?
The attacker must cause rLottie to render a crafted vector animation. The CVSS vector indicates local attack access and user interaction are required, while no privileges are required.
2
What security impact can successful exploitation have?
Successful exploitation can cause memory corruption through a stack-based buffer overflow. The reported impact includes low integrity and availability impact, with no confidentiality impact.
3
Which rLottie revision is identified as affected?
The issue is reported to affect rLottie revision 480a2ad0c5d2e45458c545b8213279e9e8b71e39.