Junglewise Threat Intelligence

CVE-2026-48298: Adobe Content Credentials integer underflow denial of service

CVE-2026-48298 · Severity: medium · CVSS 6.2 · Published 2026-07-14

Technologies: Adobe Content Credentials JS SDK, Adobe Content Credentials Rust SDK, Adobe Content Credentials Command-Line Tool. Vendors: Adobe.

Executive brief

Adobe Content Credentials tools and software development kits are affected by a security flaw that can cause applications to crash. This technology is used to verify the authenticity and origin of digital content like images and videos. An attacker could exploit this to disrupt services or prevent users from verifying digital media, though it does not appear to allow for data theft.

Technical details

An integer underflow (CWE-191) exists in the Adobe Content Authenticity Initiative (CAI) Content Credentials components, including the Rust SDK, JS SDK, and CLI tool. The vulnerability is triggered when the application processes specially crafted input, leading to a wrap-around error that results in an application crash (Denial of Service). The attack vector is classified as local, and while it does not require user interaction or specific privileges, it only impacts availability. Patches have been released in Rust SDK v0.85.2, CLI tool v0.26.65, and JS SDK v0.16.6.

Affected products

  • Adobe Content Credentials Rust SDK (c2pa) <= c2pa-v0.84.0
  • Adobe Content Credentials Command-Line Tool (c2patool) <= c2patool-v0.16.5
  • Adobe Content Credentials JS SDK (@contentauth/c2pa) <= @contentauth/c2pa-v0.16.5

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats