---
id: CVE-2026-91826
title: >-
  Stack-based buffer overflow vulnerability in Samsung Opensource rLottie allows
  attackers to overflow buffers, leading to memory corruption when rendering
  crafted vector animations.



  This issue affects rLottie: 480a2ad0c5d2e45458c545b821…
summary: >-
  Stack-based buffer overflow vulnerability in Samsung Opensource rLottie allows
  attackers to overflow buffers, leading to memory corruption when rendering
  crafted vector animations.



  This issue affects rLottie: 480a2ad0c5d2e45458c545b821…
severity: medium
cvss: 4.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'
cwe:
  - CWE-121
vendor: Samsung Opensource
product: rLottie
affected:
  - rLottie 480a2ad0c5d2e45458c545b8213279e9e8b71e39
published: '2026-09-15'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:29:56.010'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91826'
references:
  - url: 'https://github.com/Samsung/rlottie/pull/607'
    label: PSIRT@samsung.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-91826.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-91826'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-91826'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.00144
epssPercentile: 0.03044
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-15T13:32:20.742778Z'
ingestedAt: '2026-09-15T09:34:49.386Z'
---

## Overview

Stack-based buffer overflow vulnerability in Samsung Opensource rLottie allows attackers to overflow buffers, leading to memory corruption when rendering crafted vector animations.


This issue affects rLottie: 480a2ad0c5d2e45458c545b8213279e9e8b71e39.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-91826.json)
