Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads.
This issue affects rlottie: before e2d19e3b150e0e4a9586fa90b56fd3061cc98945.
{
"cna_assigner": "samsung.tv_appliance",
"cwe_ids": [
"CWE-674"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47306.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47306.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"109049672512567321477826940597791457322",
"237129202130285650073204098204968258153",
"321329525953985250548059413647565438560",
"50212813740084240778442525379782518630",
"261558236377445354010544690209005246945",
"128807687351656639006048563696097582903",
"286817249075734189427817947813445007582",
"191237667245342869134248649479860535208",
"296530015711424786938781771640784305967",
"118295041658395730940582499528558617540",
"203035243591414326498110249124668396947"
],
"threshold": 0.9
},
"id": "CVE-2026-47306-3b3305c3",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/samsung/rlottie/commit/e2d19e3b150e0e4a9586fa90b56fd3061cc98945",
"target": {
"file": "src/lottie/lottieparser.cpp"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "100422303893544090756906117199873495048",
"length": 541
},
"id": "CVE-2026-47306-dc5224d8",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/samsung/rlottie/commit/e2d19e3b150e0e4a9586fa90b56fd3061cc98945",
"target": {
"file": "src/lottie/lottieparser.cpp",
"function": "LottieParserImpl::resolveLayerRefs"
}
}
]
"2026-10-08T07:15:04Z"