Junglewise Threat Intelligence

CVE-2026-34671: Adobe CAI Content Credentials integer overflow in c2pa-web and c2pa-v

CVE-2026-34671 · Severity: medium · CVSS 6.2 · Published 2026-05-12

Technologies: Adobe C2pa, Adobe C2pa-Web, Adobe Content Credentials SDK, Adobe C2pa-Rust. Vendors: Adobe.

Executive brief

Adobe's Content Authenticity Initiative (CAI) tools, which are used to verify the origin and history of digital media, are affected by a software flaw. An attacker can exploit this vulnerability to crash applications using these tools, causing a service outage. This could prevent users from being able to verify the authenticity of images or videos, potentially impacting trust in digital content.

Technical details

An integer overflow or wraparound vulnerability (CWE-190) exists in the Adobe Content Authenticity Initiative (CAI) SDK, specifically affecting the c2pa-web and c2pa-v (Rust) implementations. The flaw is triggered during the processing of content credentials, where improper arithmetic handling can lead to an application crash. The attack vector is classified as local, meaning the attacker typically needs to provide a specially crafted file or input to be processed by the library on the local system. Successful exploitation results in a denial-of-service (DoS) state. Patches have been released in c2pa-web version 0.7.1 and c2pa-rust version 0.80.1.

Affected products

  • Adobe c2pa-web 0.7.0 and earlier
  • Adobe c2pa-rust (c2pa-v) 0.78.2 and earlier

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats