Description
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.
Published: 2026-08-11
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CAI Content Credentials is vulnerable to an uncontrolled resource consumption flaw (CWE-400) that can lead to application denial-of-service. The flaw does not require user interaction, so an attacker can trigger it remotely by sending crafted requests or invoking the command-line tool with malicious input. Based on the description, it is inferred that the attacker can trigger resource exhaustion by sending malformed or high-volume payloads, exhausting CPU or memory resources and rendering the affected applications unavailable.

Affected Systems

Adobe Content Credentials Command-Line Tool, Adobe Content Credentials JavaScript SDK, and Adobe Content Credentials Rust SDK. Any deployment of these components is potentially affected, as version numbers are not disclosed; apply a patch or remove the components.

Risk and Exploitability

The CVSS score of 6.2 classifies the vulnerability as moderate severity. The EPSS score of less than 1% indicates a low likelihood of exploitation, and it is not listed in CISA’s KEV catalog. Based on the description, it is inferred that attackers can exploit the flaw by sending malformed input or executing the command-line tool with high-volume payloads, which consumes system resources without requiring the user to interact with the application.

Generated by OpenCVE AI on August 12, 2026 at 22:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Adobe patch that addresses uncontrolled resource consumption in the Content Credentials Command-Line Tool, JS SDK, and Rust SDK as soon as it becomes available.
  • If a patch cannot be applied immediately, implement input size limits or rate limiting on the command-line interface and SDK endpoints, or otherwise reject requests that may trigger excessive resource usage.
  • Continuously monitor CPU and memory usage, and set alerts for abnormal spikes that could indicate a denial-of-service attack.

Generated by OpenCVE AI on August 12, 2026 at 22:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe c2pa
Adobe c2pa-web
Adobe c2patool
CPEs cpe:2.3:a:adobe:c2pa-web:*:*:*:*:*:node.js:*:*
cpe:2.3:a:adobe:c2pa:*:*:*:*:*:rust:*:*
cpe:2.3:a:adobe:c2patool:*:*:*:*:*:*:*:*
Vendors & Products Adobe c2pa
Adobe c2pa-web
Adobe c2patool

Thu, 13 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk
Vendors & Products Adobe
Adobe content Credentials Command-line Tool
Adobe content Credentials Js Sdk
Adobe content Credentials Rust Sdk

Tue, 11 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.
Title CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Adobe C2pa C2pa-web C2patool Content Credentials Command-line Tool Content Credentials Js Sdk Content Credentials Rust Sdk
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:34:02.719Z

Reserved: 2026-05-21T15:28:38.146Z

Link: CVE-2026-48443

cve-icon Vulnrichment

Updated: 2026-08-11T17:49:04.186Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:01.573

Modified: 2026-08-28T00:18:02.317

Link: CVE-2026-48443

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T04:15:02Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption