CVE-2026-19517

Summary

Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerability in Samsung Open Source rlottie allows Excessive Allocation.

Affected Software

VendorProductVersion RangeStatus
Samsung Open Sourcerlottief487eff2f8086b84ae1c7faa0418abec909e874bunaffected

Weaknesses

  • CWE-1284: CWE-1284 Improper Validation of Specified Quantity in Input
  • CWE-770: CWE-770 Allocation of Resources Without Limits or Throttling

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References