Junglewise Threat Intelligence

CVE-2026-34667: Adobe CAI Content Credentials integer underflow denial of service

CVE-2026-34667 · Severity: medium · CVSS 6.2 · Published 2026-05-12

Technologies: Adobe C2pa, Adobe C2pa-Web, Adobe C2pa-Rust. Vendors: Adobe.

Executive brief

Adobe CAI Content Credentials, a toolset used to verify the authenticity and origin of digital content, is affected by a software flaw. An attacker could exploit this vulnerability to cause applications using these tools to crash unexpectedly. This results in a denial-of-service, preventing users from verifying content credentials or using related features until the application is restarted.

Technical details

An integer underflow (CWE-191) exists in the Adobe Content Authenticity Initiative (CAI) SDK, specifically affecting the c2pa-web (Node.js) and c2pa (Rust) implementations. The vulnerability is triggered during the processing of content credentials, where a wrap-around error leads to an application crash. The attack vector is classified as local, meaning an attacker must be able to provide a malicious payload to the affected application. Exploitation does not require administrative privileges or user interaction. Successful exploitation results in a denial-of-service (DoS) condition. Patches are available in c2pa-web version 0.7.1 and c2pa version 0.80.1.

Affected products

  • Adobe c2pa-web <= 0.7.0
  • Adobe c2pa-rust (c2pa) <= 0.78.2

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats