Junglewise Threat Intelligence

CVE-2026-34677: Adobe CAI Content Credentials uncontrolled resource consumption

CVE-2026-34677 · Severity: medium · CVSS 6.2 · Published 2026-05-12

Technologies: Adobe C2pa, Adobe C2pa-Web, Adobe Content Credentials SDK, Adobe C2pa-Rust. Vendors: Adobe.

Executive brief

Adobe CAI Content Credentials, a toolset used to verify the authenticity of digital content, is affected by a resource management flaw. An attacker can exploit this to exhaust system memory or processing power, causing the application to crash or become unresponsive. This results in a denial-of-service, preventing users from verifying content provenance or using the affected software.

Technical details

An uncontrolled resource consumption vulnerability (CWE-400) exists in the Adobe Content Authenticity Initiative (CAI) SDK. The flaw affects both the Node.js (c2pa-web) and Rust (c2pa-v) implementations. An attacker can exploit this vulnerability locally without requiring user interaction to exhaust system resources. This leads to a denial-of-service (DoS) condition for the host application. The issue is addressed in c2pa-web version 0.7.1 and c2pa-rust version 0.80.1.

Affected products

  • Adobe c2pa-web <= 0.7.0
  • Adobe c2pa-rust (c2pa-v) <= 0.78.2

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats