{"id":"CVE-2026-47306","details":"Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads.\n\nThis issue affects rlottie: before e2d19e3b150e0e4a9586fa90b56fd3061cc98945.","modified":"2026-10-08T07:15:04.460748417Z","published":"2026-06-04T09:43:14.593Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47306.json","cna_assigner":"samsung.tv_appliance","cwe_ids":["CWE-674"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47306.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47306"},{"type":"FIX","url":"https://github.com/Samsung/rlottie/pull/585"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/samsung/rlottie","events":[{"introduced":"0"},{"fixed":"e2d19e3b150e0e4a9586fa90b56fd3061cc98945"}]}],"database_specific":{"vanir_signatures_modified":"2026-10-08T07:15:04Z","source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47306.json","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["109049672512567321477826940597791457322","237129202130285650073204098204968258153","321329525953985250548059413647565438560","50212813740084240778442525379782518630","261558236377445354010544690209005246945","128807687351656639006048563696097582903","286817249075734189427817947813445007582","191237667245342869134248649479860535208","296530015711424786938781771640784305967","118295041658395730940582499528558617540","203035243591414326498110249124668396947"],"threshold":0.9},"id":"CVE-2026-47306-3b3305c3","signature_type":"Line","signature_version":"v1","source":"https://github.com/samsung/rlottie/commit/e2d19e3b150e0e4a9586fa90b56fd3061cc98945","target":{"file":"src/lottie/lottieparser.cpp"}},{"target":{"file":"src/lottie/lottieparser.cpp","function":"LottieParserImpl::resolveLayerRefs"},"deprecated":false,"digest":{"function_hash":"100422303893544090756906117199873495048","length":541},"id":"CVE-2026-47306-dc5224d8","signature_type":"Function","signature_version":"v1","source":"https://github.com/samsung/rlottie/commit/e2d19e3b150e0e4a9586fa90b56fd3061cc98945"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"}]}