Executive brief
Adobe Content Credentials, a toolset used to verify the authenticity and origin of digital content, is affected by a flaw that allows for resource exhaustion. An attacker can exploit this to crash the application or make it unresponsive, leading to a denial-of-service. This could disrupt workflows that rely on verifying digital media provenance and metadata.
Technical details
An uncontrolled resource consumption vulnerability (CWE-400) exists in the Adobe Content Authenticity Initiative (CAI) Content Credentials SDK. The flaw affects the c2pa-web (v0.7.1 and earlier) and c2pa-v (v0.80.1 and earlier) components. An attacker can exploit this vulnerability to exhaust system resources, resulting in an application-level denial-of-service (DoS). The attack vector is classified as local, and exploitation does not require user interaction or specific privileges. A fix is available via Adobe security bulletin APSB26-61.
Affected products
- Adobe Content Credentials (c2pa-web) 0.7.1 and earlier
- Adobe Content Credentials (c2pa-v) 0.80.1 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory: Adobe published APSB26-61