Impact
The vulnerability is an uncontrolled resource consumption flaw that lets an attacker trigger a denial‑of‑service condition without any user interaction. By sending crafted requests, an attacker can exhaust system resources such as memory or processing power, leading to application instability or failure.
Affected Systems
Adobe CAI Content Credentials versions 0.78.2, 0.7.0 and all earlier releases are affected.
Risk and Exploitability
The CVSS score of 6.2 indicates moderate severity, and the EPSS score of <1% signals a very low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. An attacker can exploit the vulnerability remotely by repeatedly invoking the vulnerable endpoint, consuming system resources, and crashing the application.
OpenCVE Enrichment