Executive brief
Adobe CAI Content Credentials, a toolset used to verify the authenticity and origin of digital content, is affected by a flaw that allows for resource exhaustion. An attacker can exploit this to crash applications or services using the SDK, leading to a denial-of-service. This could disrupt the ability of platforms to validate media provenance without requiring any user interaction.
Technical details
An uncontrolled resource consumption vulnerability (CWE-400) exists in the Adobe Content Authenticity Initiative (CAI) SDKs, specifically c2pa-web and the Rust-based c2pa-v. The flaw allows a remote, unauthenticated attacker to trigger excessive system resource usage, resulting in a denial-of-service (DoS) condition. The attack is network-based and requires no user interaction or special privileges. According to NVD data, the issue is addressed in c2pa-web version 0.7.1 and c2pa-v version 0.80.1.
Affected products
- Adobe c2pa-web <= 0.7.0
- Adobe c2pa-v (Rust SDK) <= 0.78.2
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory