SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82797

MEDIUM · CVSS 5.5 EPSS 0.10% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-31 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

An uncontrolled recursion vulnerability in Samsung's rlottie library allows for the processing of serialized data with nested payloads, potentially leading to excessive resource consumption and application crashes. This issue affects versions prior to the specified commit and poses a medium risk, making it essential for developers and organizations utilizing rlottie in their applications to prioritize remediation efforts.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82797
Severity
MEDIUM
CVSS
5.5
EPSS
0.10%

Original NVD Description

Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Serialized Data with Nested Payloads. This issue affects rlottie: before 8de0d9e6ca80ffef654965505981727b9fa06a51.