CVE-2026-18772CWE-1325

CVE-2026-18772

Medium · published August 4, 2026

CVSS v3.1
6.5
EPSS
0%
Percentile
9.8
In the wild
Unconfirmed
What it is

Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion.

The record
Technical detail
CVSS v3.1
6.5 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.00199 · 9.8th percentile
Weakness
CWE-1325 · Improperly Controlled Sequential Memory Allocation
Published
2026-08-04T14:19Z
References (1)
EPSS history
Timeline
  • 04 AUG 08:22Z
    Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion
    cvelistv5