Improper Input Validation and Resource Allocation in Samsung Open Source rlottie
CVE-2026-19517

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-19517?

The Samsung Open Source rlottie library suffers from an improper validation of specified input quantity, leading to potential excessive resource allocation. This vulnerability allows attackers to exploit the inadequacies in input handling, potentially causing system instability or denial of service due to uncontrolled resource consumption.

Affected Version(s)

rlottie f487eff2f8086b84ae1c7faa0418abec909e874b

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.