Junglewise Threat Intelligence

CVE-2026-34665: Adobe CAI Content Credentials denial of service via resource consumption

CVE-2026-34665 · Severity: high · CVSS 7.5 · Published 2026-05-12

Technologies: Adobe C2pa, Adobe C2pa-Web, Adobe c2pa-v (Rust SDK), Adobe Content Credentials SDK. Vendors: Adobe.

Executive brief

Adobe CAI Content Credentials, a toolset used to verify the authenticity and origin of digital content, is affected by a flaw that allows for resource exhaustion. An attacker can exploit this to crash applications or services using the SDK, leading to a denial-of-service. This could disrupt the ability of platforms to validate media provenance without requiring any user interaction.

Technical details

An uncontrolled resource consumption vulnerability (CWE-400) exists in the Adobe Content Authenticity Initiative (CAI) SDKs, specifically c2pa-web and the Rust-based c2pa-v. The flaw allows a remote, unauthenticated attacker to trigger excessive system resource usage, resulting in a denial-of-service (DoS) condition. The attack is network-based and requires no user interaction or special privileges. According to NVD data, the issue is addressed in c2pa-web version 0.7.1 and c2pa-v version 0.80.1.

Affected products

  • Adobe c2pa-web <= 0.7.0
  • Adobe c2pa-v (Rust SDK) <= 0.78.2

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats