{"affected":[{"affectedData":[{"defaultStatus":"unaffected","product":"rlottie","vendor":"Samsung Open Source","versions":[{"status":"unaffected","version":"f487eff2f8086b84ae1c7faa0418abec909e874b"}]}],"source":"PSIRT@samsung.com"}],"configurations":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:samsung:rlottie:-:*:*:*:*:*:*:*","matchCriteriaId":"839F9D6A-5E2B-4FDF-9F6F-CB9D3ED281F0","vulnerable":true}],"negate":false,"operator":"OR"}]}],"cveTags":[],"descriptions":[{"lang":"en","value":"Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie allows Input Data Manipulation."}],"id":"CVE-2026-19518","lastModified":"2026-09-23T15:44:22.137","metrics":{"cvssMetricV31":[{"cvssData":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","version":"3.1"},"exploitabilityScore":2.8,"impactScore":3.6,"source":"PSIRT@samsung.com","type":"Secondary"}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"id":"CVE-2026-19518","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-08-11T16:55:21.611977Z","version":"2.0.3"}}]},"published":"2026-08-11T07:17:29.883","references":[{"source":"PSIRT@samsung.com","tags":["Patch","Vendor Advisory"],"url":"https://github.com/Samsung/rlottie/pull/596"}],"sourceIdentifier":"PSIRT@samsung.com","vulnStatus":"Analyzed","weaknesses":[{"description":[{"lang":"en","value":"CWE-1284"}],"source":"PSIRT@samsung.com","type":"Secondary"}]}