Description
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.
Published: 2026-08-25
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The vulnerability allows an attacker to trigger uncontrolled resource consumption, causing the application to exhaust CPU, memory or other system resources. This results in a denial‑of‑service condition in which the affected program becomes unavailable or unusable. The flaw is identified as a CWE‑400 resource exhaustion weakness and can be triggered without any user interaction.

Affected Systems

Adobe’s C2PA Tool and Adobe Content Credentials Rust SDK are impacted. No specific version information is supplied, so all releases of these products are susceptible until a patch is applied.

Risk and Exploitability

With a CVSS score of 7.5 the risk is considered high; the EPSS score is not provided and the issue is not listed in CISA’s KEV catalog. The attack vector is inferred to be remote, likely through crafted content or requests sent to the tool, since user interaction is not required. If exploited, the application will become unresponsive, potentially affecting services that depend on it.

Generated by OpenCVE AI on August 25, 2026 at 20:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe update for the C2PA Tool and Content Credentials Rust SDK as soon as it becomes available.
  • Implement request throttling or rate limiting on input processing paths to constrain the rate at which resource‑intensive operations can be invoked.
  • Configure monitoring and alerting to detect abnormal spikes in CPU or memory usage, and enforce automatic restart or shutdown policies for the service when thresholds are exceeded.

Generated by OpenCVE AI on August 25, 2026 at 20:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe c2pa
Adobe c2patool
CPEs cpe:2.3:a:adobe:c2pa:*:*:*:*:*:rust:*:*
cpe:2.3:a:adobe:c2patool:*:*:*:*:*:*:*:*
Vendors & Products Adobe
Adobe c2pa
Adobe c2patool

Wed, 26 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Description CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.
Title CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:32:51.025Z

Reserved: 2026-08-05T23:51:57.377Z

Link: CVE-2026-71360

cve-icon Vulnrichment

Updated: 2026-08-26T18:52:29.791Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T18:18:00.163

Modified: 2026-09-09T13:42:38.063

Link: CVE-2026-71360

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T20:45:04Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption