Executive brief
Adobe CAI Content Credentials, a toolset used to verify the authenticity and origin of digital content, is affected by a security flaw that can cause applications to crash. By providing specially crafted input, an attacker can trigger a denial-of-service condition, making the verification service unavailable. This impact is limited to service availability and does not involve the theft of sensitive customer data.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Adobe Content Authenticity Initiative (CAI) SDKs, specifically the c2pa-web (Node.js) and c2pa-v (Rust) implementations. The flaw allows a local attacker to provide malformed data that the library fails to process safely, leading to an application crash. The attack vector is classified as local, but it does not require specific user interaction or elevated privileges to trigger the denial-of-service condition. Patches are available in c2pa-web version 0.7.1 and c2pa-v (Rust) version 0.80.1.
Affected products
- Adobe c2pa-web 0.7.0 and earlier
- Adobe c2pa-v (Rust SDK) 0.78.2 and earlier
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory