Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Serialized Data with Nested Payloads.
This issue affects rlottie: before 8de0d9e6ca80ffef654965505981727b9fa06a51.
{
"cna_assigner": "samsung.tv_appliance",
"cwe_ids": [
"CWE-674"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82797.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82797.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "165477875175686595012492847257698666774",
"length": 823
},
"id": "CVE-2026-82797-4f5cea73",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/samsung/rlottie/commit/8de0d9e6ca80ffef654965505981727b9fa06a51",
"target": {
"file": "src/lottie/lottieparser.cpp",
"function": "LottieParserImpl::parseGroupObject"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"3270914981905464508614041780813690206",
"10533135866123781050764972674486003156",
"89485184120685631933638149552712561958",
"171559662381363971731726697892314817256",
"145689586090703069167208076344910832276",
"143717762820069605831522460727606015817",
"340070422019916217703340100510662775988",
"122563825636038882594005758527456705645",
"82754120089104293328240141528079461456",
"86079765523972876366376107265985428818",
"256381032833248048927638519471410184419",
"324400458097072797366463945618656997019",
"31024569588367764023374328533780132988",
"261533773973370965625946251949851511563",
"41546319736947617630882011835476410486"
],
"threshold": 0.9
},
"id": "CVE-2026-82797-5195903d",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/samsung/rlottie/commit/8de0d9e6ca80ffef654965505981727b9fa06a51",
"target": {
"file": "src/lottie/lottieparser.cpp"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"248751173952086816211398028741007879528",
"4849998269134322798580524679736147800",
"88432152888640206842021231350340237609",
"335136385223389897421599186800671270916"
],
"threshold": 0.9
},
"id": "CVE-2026-82797-5f6d80a2",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/samsung/rlottie/commit/8de0d9e6ca80ffef654965505981727b9fa06a51",
"target": {
"file": "src/lottie/lottiemodel.cpp"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"206684468719099779356549093820309945665",
"77319607010456995319413684786491136754",
"4471865659794436313212812027572248576"
],
"threshold": 0.9
},
"id": "CVE-2026-82797-7209fd30",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/samsung/rlottie/commit/8de0d9e6ca80ffef654965505981727b9fa06a51",
"target": {
"file": "src/lottie/lottiemodel.h"
}
}
]
"2026-10-08T07:15:23Z"