Impact
CAI Content Credentials, a tool and SDK suite from Adobe, has an uncontrolled resource consumption flaw (CWE‑400) that may allow attackers to exhaust system resources and cause a denial‑of‑service condition in the affected services.
Affected Systems
Adobe Content Credentials Command‑Line Tool, Adobe Content Credentials JavaScript SDK, and Adobe Content Credentials Rust SDK are identified as affected. The CNA does not provide explicit version ranges, so any deployed instance should be verified against the vendor’s advisories.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, yet the EPSS score of less than 1% signals a low probability of exploitation in the wild. The vulnerability can be triggered remotely without user interaction. The likely attack vector is sending specially crafted requests to the exposed endpoints, which may consume CPU, memory, or other resources until the application becomes unavailable. The issue is not yet listed in the CISA KEV catalog.
OpenCVE Enrichment