Junglewise Threat Intelligence

CVE-2026-34679: Adobe CAI Content Credentials denial of service via improper input validation

CVE-2026-34679 · Severity: medium · CVSS 6.2 · Published 2026-05-12

Technologies: Adobe C2pa, Adobe C2pa-Web, Adobe Content Credentials SDK, Adobe c2pa-v (Rust SDK). Vendors: Adobe.

Executive brief

Adobe CAI Content Credentials, a toolset used to verify the authenticity and origin of digital content, is affected by a security flaw that can cause applications using it to crash. An attacker could provide specially crafted data to trigger this failure, resulting in a denial-of-service. This impact prevents users from verifying content credentials and may disrupt workflows that rely on this security metadata.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Adobe Content Authenticity Initiative (CAI) SDKs, specifically the c2pa-web (Node.js) and c2pa (Rust) implementations. The flaw allows an attacker to provide malformed input that the library fails to process safely, leading to an application crash. The attack vector is classified as local, meaning the malicious input must be processed by a local instance of the library, but it requires no special privileges or user interaction to trigger the denial-of-service condition. Patches have been released in c2pa-web version 0.7.1 and c2pa version 0.80.1.

Affected products

  • Adobe c2pa-web <= 0.7.0
  • Adobe c2pa-v (Rust SDK) <= 0.78.2

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory
  • 2026-05-15: patched: NIST records indicate patches in c2pa-web 0.7.1 and c2pa 0.80.1

References

Related threats