{
  "threat_severity" : "Moderate",
  "public_date" : "2026-08-12T02:14:59Z",
  "bugzilla" : {
    "description" : "rlottie: rlottie: Denial of Service due to excessive resource allocation",
    "id" : "2514466",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2514466"
  },
  "cvss3" : {
    "cvss3_base_score" : "6.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
    "status" : "draft"
  },
  "cwe" : "CWE-1050",
  "details" : [ "Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation.", "A flaw was found in rlottie, an open-source animation library. This uncontrolled resource consumption vulnerability allows a remote attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted input that leads to excessive memory or CPU allocation. This can make the affected system or application unresponsive or crash." ],
  "statement" : "Moderate: This flaw in the rlottie animation library can lead to a Denial of Service due to excessive resource allocation when processing specially crafted input. Exploitation requires user interaction, as an attacker must trick a user into opening a malicious animation file. This limits the attack vector, preventing unauthenticated, unassisted remote exploitation.",
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-19587\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-19587\nhttps://github.com/Samsung/rlottie/pull/599" ],
  "name" : "CVE-2026-19587",
  "mitigation" : {
    "value" : "To mitigate this issue, avoid processing untrusted or maliciously crafted Lottie animation files. Exercise caution when opening or interacting with Lottie animations from unknown or unverified sources, as user interaction is required for exploitation. This operational control helps prevent resource exhaustion in applications utilizing rlottie.",
    "lang" : "en:us"
  },
  "csaw" : false
}