← Back to search

CVE-2026-18772

6.5 MEDIUMpublic exploit available

Published 2026-08-04 · Updated 2026-08-11

AI risk analysis

Summary
The flaw involves an improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie, allowing for exponential data expansion and potential denial of service.
Exploitability
Exploitation requires specific conditions but is relatively straightforward given the vulnerability's nature.
Blast radius
If exploited, this could lead to significant system resource exhaustion, impacting performance or causing a denial of service.
Prioritized remediation
Update rlottie to a patched version as soon as possible to mitigate the risk.
dosmemory-expansionpatch-recommended

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Weaknesses

CWE-1325

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.