Junglewise Threat Intelligence

CVE-2026-34688: Adobe CAI Content Credentials denial of service via improper input validation

CVE-2026-34688 · Severity: medium · CVSS 6.2 · Published 2026-05-12

Technologies: Adobe C2pa, Adobe C2pa-Web, Adobe Content Credentials SDK, Adobe c2pa-v (Rust SDK). Vendors: Adobe.

Executive brief

Adobe CAI Content Credentials, a toolset used to verify the authenticity and origin of digital content, is affected by a security flaw that can cause applications to crash. By providing specially crafted input, an attacker can trigger a denial-of-service condition, making the verification service unavailable. This impact is limited to service availability and does not involve the theft of sensitive customer data.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Adobe Content Authenticity Initiative (CAI) SDKs, specifically the c2pa-web (Node.js) and c2pa-v (Rust) implementations. The flaw allows a local attacker to provide malformed data that the library fails to process safely, leading to an application crash. The attack vector is classified as local, but it does not require specific user interaction or elevated privileges to trigger the denial-of-service condition. Patches are available in c2pa-web version 0.7.1 and c2pa-v (Rust) version 0.80.1.

Affected products

  • Adobe c2pa-web 0.7.0 and earlier
  • Adobe c2pa-v (Rust SDK) 0.78.2 and earlier

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats