Junglewise Threat Intelligence

CVE-2026-48357: Adobe Content Credentials denial of service via resource exhaustion

CVE-2026-48357 · Severity: medium · CVSS 6.2 · Published 2026-07-14

Technologies: Adobe Content Credentials JS SDK, Adobe Content Credentials Rust SDK, Adobe Content Credentials Command-Line Tool. Vendors: Adobe.

Executive brief

Adobe Content Credentials, a toolset used to verify the authenticity and origin of digital content, is affected by a resource management flaw. An attacker could exploit this to crash the application or make it unresponsive by exhausting system resources. This results in a denial-of-service, preventing users from verifying content credentials, though it does not directly expose private data.

Technical details

An uncontrolled resource consumption vulnerability (CWE-400) exists in the Adobe Content Authenticity (CAI) SDKs and command-line tools. The flaw allows a local attacker to trigger excessive resource usage, leading to a denial-of-service (DoS) state for the affected application. The vulnerability impacts the Rust SDK (up to v0.84.0), the JS SDK (up to v0.16.5), and the C2PA command-line tool (up to v0.16.5). Exploitation does not require user interaction. Patches have been released in Rust SDK v0.85.2, JS SDK v0.16.6, and C2PA Tool v0.26.65.

Affected products

  • Adobe Content Credentials Rust SDK <= c2pa-v0.84.0
  • Adobe Content Credentials Command-Line Tool <= c2patool-v0.16.5
  • Adobe Content Credentials JS SDK <= @contentauth/c2pa-v0.16.5

Timeline

  • 2026-07-14: advisory
  • 2026-07-14: disclosed

References

Related threats