Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19587

Опубликовано: 12 авг. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation.

A flaw was found in rlottie, an open-source animation library. This uncontrolled resource consumption vulnerability allows a remote attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted input that leads to excessive memory or CPU allocation. This can make the affected system or application unresponsive or crash.

Отчет

Moderate: This flaw in the rlottie animation library can lead to a Denial of Service due to excessive resource allocation when processing specially crafted input. Exploitation requires user interaction, as an attacker must trick a user into opening a malicious animation file. This limits the attack vector, preventing unauthenticated, unassisted remote exploitation.

Меры по смягчению последствий

To mitigate this issue, avoid processing untrusted or maliciously crafted Lottie animation files. Exercise caution when opening or interacting with Lottie animations from unknown or unverified sources, as user interaction is required for exploitation. This operational control helps prevent resource exhaustion in applications utilizing rlottie.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1050
https://bugzilla.redhat.com/show_bug.cgi?id=2514466rlottie: rlottie: Denial of Service due to excessive resource allocation

EPSS

Процентиль: 10%
0.00199
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
4 дня назад

Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation.

CVSS3: 6.5
nvd
5 дней назад

Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation.

CVSS3: 6.5
debian
5 дней назад

Uncontrolled Resource Consumption vulnerability in Samsung Open Source ...

CVSS3: 6.5
github
5 дней назад

Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation.

EPSS

Процентиль: 10%
0.00199
Низкий

6.5 Medium

CVSS3