CVE-2026-18772

Summary

Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion.

Affected Software

VendorProductVersion RangeStatus
Samsung Open Sourcerlottief487eff2f8086b84ae1c7faa0418abec909e874bunaffected

Weaknesses

  • CWE-1325: CWE-1325 Improperly controlled sequential memory allocation

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References