Executive brief
Adobe Content Credentials, a toolset used to verify the authenticity and provenance of digital content, is affected by a vulnerability that can cause applications to crash. An attacker could provide specially crafted input that triggers a denial-of-service, preventing users from verifying media or using related command-line tools. This issue impacts the reliability of content attribution workflows but does not involve the theft of private data.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Adobe Content Authenticity (CAI) SDKs and command-line tools. The flaw allows a local attacker to provide malformed input that the application fails to process correctly, leading to an unexpected crash and denial-of-service (DoS) condition. The vulnerability affects the Rust SDK, JavaScript SDK, and the C2PA command-line tool. No user interaction is required for exploitation beyond the application processing the malicious input. Patches have been released in Rust SDK v0.85.2, C2PA Tool v0.26.65, and JS SDK v0.27.0.
Affected products
- Adobe Content Credentials Rust SDK <= c2pa-v0.84.0
- Adobe Content Credentials Command-Line Tool <= c2patool-v0.16.5
- Adobe Content Credentials JS SDK <= @contentauth/c2pa-v0.26.0
Timeline
- 2026-07-14: advisory
- 2026-07-14: disclosed