Junglewise Threat Intelligence

CVE-2026-34672: Adobe CAI Content Credentials integer underflow leading to DoS

CVE-2026-34672 · Severity: medium · CVSS 6.2 · Published 2026-05-12

Technologies: Adobe C2pa, Adobe C2pa-Rs, Adobe C2pa-Web, Adobe Content Credentials SDK. Vendors: Adobe.

Executive brief

Adobe CAI Content Credentials, a toolset used to verify the authenticity and origin of digital media, is affected by a software flaw that can cause applications to crash. An attacker could exploit this vulnerability to trigger a denial-of-service, preventing users from verifying content or using the affected software. This impact is limited to service availability and does not involve the theft of personal data.

Technical details

An integer underflow (CWE-191) exists in the Adobe Content Authenticity Initiative (CAI) Content Credentials SDK (c2pa-rs and c2pa-web). The vulnerability occurs when the software performs a subtraction operation that results in a value smaller than the minimum possible integer, leading to a wrap-around. This flaw can be triggered by a local attacker to cause an application crash, resulting in a denial-of-service (DoS) condition. The exploit does not require user interaction or elevated privileges. Patches are available in c2pa-web version 0.7.1 and c2pa-rs version 0.80.1.

Affected products

  • Adobe c2pa-web 0.7.0 and earlier
  • Adobe c2pa-rs (Content Credentials SDK) 0.78.2 and earlier

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats