Description
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.
Published: 2026-08-11
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An uncontrolled resource consumption flaw in Adobe Content Credentials allows an attacker to exhaust system resources, causing the affected application to become unresponsive. The vulnerability does not require user interaction and can be leveraged by simply sending specially crafted input or requests to the affected components, leading to a denial of service condition. The primary impact is loss of availability for the services that rely on the Content Credentials tool, JS SDK, or Rust SDK.

Affected Systems

The vulnerability affects Adobe Content Credentials Command-Line Tool, Adobe Content Credentials JavaScript Software Development Kit, and Adobe Content Credentials Rust Software Development Kit. No specific product versions are cited in the available information, so all current instances of these components should be considered potentially vulnerable.

Risk and Exploitability

The CVSS score of 6.2 indicates moderate severity. The EPSS score of less than 1% suggests that, although the flaw could be highly damaging if exploited, it is unlikely to be actively targeted or exploited in the wild. The vulnerability is not listed in the CISA KEV catalog, further indicating low immediate threat. Nonetheless, because exploitation does not require user interaction, an attacker could trigger it from a remote location, leading to a denial of service of the entire application.

Generated by OpenCVE AI on August 12, 2026 at 21:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Confirm and install the latest Adobe Content Credentials updates or patches provided by Adobe for the Command-Line Tool, JS SDK, or Rust SDK
  • Apply system or container resource limits to the tool, such as CPU, memory, or file descriptor quotas, to prevent a single instance from consuming excessive resources
  • Monitor application and system resource usage for sudden spikes and set alerts to detect abnormal consumption patterns

Generated by OpenCVE AI on August 12, 2026 at 21:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe c2pa
Adobe c2pa-web
Adobe c2patool
CPEs cpe:2.3:a:adobe:c2pa-web:*:*:*:*:*:node.js:*:*
cpe:2.3:a:adobe:c2pa:*:*:*:*:*:rust:*:*
cpe:2.3:a:adobe:c2patool:*:*:*:*:*:*:*:*
Vendors & Products Adobe c2pa
Adobe c2pa-web
Adobe c2patool

Thu, 13 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk
Vendors & Products Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk

Wed, 12 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.
Title CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Adobe C2pa C2pa-web C2patool Content Credentials Command-line Tool Content Credentials Js Sdk Content Credentials Rust Sdk
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:34:08.432Z

Reserved: 2026-05-21T15:28:38.146Z

Link: CVE-2026-48434

cve-icon Vulnrichment

Updated: 2026-08-12T14:15:03.874Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:00.563

Modified: 2026-08-28T00:18:01.257

Link: CVE-2026-48434

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T01:30:04Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption