Executive brief
Adobe Content Credentials (CAI) tools are used to verify the origin and history of digital media to ensure authenticity. A security flaw in these tools allows a remote attacker to overwhelm the system's resources, such as memory or processing power. This can lead to a denial-of-service, making the application or verification service unavailable to legitimate users.
Technical details
An uncontrolled resource consumption vulnerability (CWE-400) exists in the Adobe Content Authenticity SDK (specifically the c2pa-web and c2pa-rs implementations). The flaw allows a remote, unauthenticated attacker to send specially crafted requests or data that exhaust system resources. This results in a denial-of-service (DoS) condition for the affected application. The attack can be carried out over the network without any user interaction. Adobe has addressed this in APSB26-61; users should update to the latest versions of the SDK.
Affected products
- Adobe Content Authenticity SDK (c2pa-web) 0.7.1 and earlier
- Adobe Content Authenticity SDK (c2pa-rs) 0.80.1 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory: Adobe APSB26-61 published