Description
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.
Published: 2026-08-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CAI Content Credentials, a tool and SDK suite from Adobe, has an uncontrolled resource consumption flaw (CWE‑400) that may allow attackers to exhaust system resources and cause a denial‑of‑service condition in the affected services.

Affected Systems

Adobe Content Credentials Command‑Line Tool, Adobe Content Credentials JavaScript SDK, and Adobe Content Credentials Rust SDK are identified as affected. The CNA does not provide explicit version ranges, so any deployed instance should be verified against the vendor’s advisories.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, yet the EPSS score of less than 1% signals a low probability of exploitation in the wild. The vulnerability can be triggered remotely without user interaction. The likely attack vector is sending specially crafted requests to the exposed endpoints, which may consume CPU, memory, or other resources until the application becomes unavailable. The issue is not yet listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 13, 2026 at 02:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and apply any patch or update for Adobe Content Credentials as soon as it becomes available.
  • Restrict network access to the affected services to trusted IP addresses or through a VPN to reduce the attack surface.
  • Implement rate limiting and monitoring on the Content Credentials endpoints to detect and mitigate resource exhaustion attempts.

Generated by OpenCVE AI on August 13, 2026 at 02:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe c2pa
Adobe c2pa-web
Adobe c2patool
CPEs cpe:2.3:a:adobe:c2pa-web:*:*:*:*:*:node.js:*:*
cpe:2.3:a:adobe:c2pa:*:*:*:*:*:rust:*:*
cpe:2.3:a:adobe:c2patool:*:*:*:*:*:*:*:*
Vendors & Products Adobe c2pa
Adobe c2pa-web
Adobe c2patool

Thu, 13 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk
Vendors & Products Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk

Wed, 12 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.
Title CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Adobe C2pa C2pa-web C2patool Content Credentials Command-line Tool Content Credentials Js Sdk Content Credentials Rust Sdk
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:34:15.662Z

Reserved: 2026-05-21T15:28:38.146Z

Link: CVE-2026-48439

cve-icon Vulnrichment

Updated: 2026-08-12T14:16:48.940Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:01.207

Modified: 2026-08-28T00:18:01.810

Link: CVE-2026-48439

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T02:45:03Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption