Executive brief
Adobe CAI Content Credentials, a toolset used to verify the authenticity and origin of digital content, is affected by a security flaw that can cause applications using it to crash. An attacker could exploit this to disrupt services or prevent users from verifying digital media. This issue affects the underlying software libraries used by developers to integrate content authenticity features into web and desktop applications.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Adobe Content Authenticity Initiative (CAI) SDK, specifically affecting the c2pa-web (Node.js) and c2pa (Rust) libraries. The flaw allows an attacker to provide specially crafted input that triggers an application crash, resulting in a denial-of-service (DoS) condition. The attack vector is classified as local, meaning the malicious input must be processed by the local environment, but it requires no special privileges or user interaction to trigger the crash. Patches are available in c2pa-web version 0.7.1 and c2pa-rust version 0.80.1.
Affected products
- Adobe c2pa-web <= 0.7.0
- Adobe c2pa-rust (c2pa-v) <= 0.78.2
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory
- 2026-06-09: other: Advisory updated with enriched product version data.