Impact
The vulnerability in Adobe CAI Content Credentials, affecting c2pa-web@0.7.0, c2pa-v0.78.2 and earlier, is an uncontrolled resource consumption flaw that can lead to application denial-of-service. An attacker could exhaust system resources, resulting in a denial-of-service condition. This flaw does not require user interaction.
Affected Systems
Adobe CAI Content Credentials versions 0.78.2, 0.7.0 and any earlier releases are affected. Affected deployments include all installations of the Content Authenticity SDK that reference those version strings.
Risk and Exploitability
The CVSS score of 6.2 indicates a moderate severity. Given an EPSS score of < 1%, the likelihood of exploitation remains low, but the flaw can be triggered simply by sending resource‑intensive requests from the network and does not require privileged access. The vulnerability is not listed in the CISA KEV catalog, but its moderate CVSS and the lack of a defensive patch in current releases suggest that organizations should treat it with priority and avoid exposure while a fix is forthcoming.
OpenCVE Enrichment