Executive brief
Adobe CAI Content Credentials, a toolset used to verify the authenticity and origin of digital content, is affected by a flaw that allows for resource exhaustion. An attacker can exploit this to crash applications or make them unresponsive, potentially disrupting workflows that rely on verifying digital media. This issue does not require any user interaction to trigger.
Technical details
The Adobe Content Authenticity Initiative (CAI) SDKs, specifically the Rust (c2pa-v) and Web (c2pa-web) implementations, contain a CWE-400 vulnerability involving uncontrolled resource consumption. The flaw allows an attacker to trigger excessive system resource usage, resulting in an application-level denial-of-service (DoS). The attack vector is classified as local, meaning the attacker must have the ability to provide input to the affected library on the host system. No user interaction or specific privileges are required to trigger the exhaustion. Patches are available in c2pa-web 0.7.1 and c2pa-v 0.80.1.
Affected products
- Adobe c2pa-web <= 0.7.0
- Adobe c2pa-v (Rust SDK) <= 0.78.2
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory