{"affected":[{"affectedData":[{"defaultStatus":"unaffected","product":"rlottie","vendor":"Samsung Open Source","versions":[{"status":"unaffected","version":"f487eff2f8086b84ae1c7faa0418abec909e874b"}]}],"source":"PSIRT@samsung.com"}],"configurations":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:samsung:rlottie:-:*:*:*:*:*:*:*","matchCriteriaId":"839F9D6A-5E2B-4FDF-9F6F-CB9D3ED281F0","vulnerable":true}],"negate":false,"operator":"OR"}]}],"cveTags":[],"descriptions":[{"lang":"en","value":"Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion."}],"id":"CVE-2026-18772","lastModified":"2026-09-23T15:59:32.730","metrics":{"cvssMetricV31":[{"cvssData":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","version":"3.1"},"exploitabilityScore":2.8,"impactScore":3.6,"source":"PSIRT@samsung.com","type":"Secondary"}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"id":"CVE-2026-18772","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-08-04T13:16:08.111242Z","version":"2.0.3"}}]},"published":"2026-08-04T10:19:32.923","references":[{"source":"PSIRT@samsung.com","tags":["Patch"],"url":"https://github.com/Samsung/rlottie/pull/596"}],"sourceIdentifier":"PSIRT@samsung.com","vulnStatus":"Analyzed","weaknesses":[{"description":[{"lang":"en","value":"CWE-1325"}],"source":"PSIRT@samsung.com","type":"Secondary"}]}