CVE-2026-18772CWE-1325
CVE-2026-18772
Medium · published August 4, 2026
What it is
Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion.
The record
Technical detail
- CVSS v3.1
- 6.5 · MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- CVSS v4.0
- Not supplied
- EPSS
- 0.00199 · 9.8th percentile
- Weakness
- CWE-1325 · Improperly Controlled Sequential Memory Allocation
- Published
- 2026-08-04T14:19Z
References (1)
EPSS history
Timeline