Input Data Manipulation Vulnerability in Samsung Open Source rlottie
CVE-2026-19518

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-19518?

An input data manipulation vulnerability exists in the Samsung Open Source rlottie library, which stems from improper validation of specified input quantities. This flaw can be exploited by attackers to manipulate input data, potentially leading to unexpected behavior or security lapses within applications leveraging this library. Developers are advised to review and update their implementations to mitigate any risks associated with this vulnerability.

Affected Version(s)

rlottie f487eff2f8086b84ae1c7faa0418abec909e874b

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.