Executive brief
Adobe Content Credentials, a toolset used to verify the authenticity and origin of digital content, is affected by a flaw that allows for resource exhaustion. An attacker can exploit this to crash applications or services using the library, leading to a denial-of-service. This could disrupt workflows that rely on verifying digital media provenance without requiring any user interaction.
Technical details
An uncontrolled resource consumption vulnerability (CWE-400) exists in the Adobe Content Authenticity Initiative (CAI) Content Credentials SDK. The flaw affects the c2pa-web (v0.7.1 and earlier) and c2pa-v (v0.80.1 and earlier) components. An attacker can exploit this vulnerability to exhaust system resources, resulting in a denial-of-service (DoS) condition for the host application. The attack vector is classified as local, and exploitation does not require prior authentication or user interaction. Users are advised to review Adobe advisory APSB26-61 for patching information.
Affected products
- Adobe Content Credentials (c2pa-web) 0.7.1 and earlier
- Adobe Content Credentials (c2pa-v) 0.80.1 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory