Description
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.
Published: 2026-08-25
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to trigger uncontrolled resource consumption, causing the application to exhaust CPU, memory or other system resources. This results in a denial‑of‑service condition in which the affected program becomes unavailable or unusable. The flaw is identified as a CWE‑400 resource exhaustion weakness and can be triggered without any user interaction.

Affected Systems

Adobe’s C2PA Tool and Adobe Content Credentials Rust SDK are impacted. No specific version information is supplied, so all releases of these products are susceptible until a patch is applied.

Risk and Exploitability

With a CVSS score of 7.5 the risk is considered high; the EPSS score is not provided and the issue is not listed in CISA’s KEV catalog. The attack vector is inferred to be remote, likely through crafted content or requests sent to the tool, since user interaction is not required. If exploited, the application will become unresponsive, potentially affecting services that depend on it.

Generated by OpenCVE AI on August 25, 2026 at 19:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe update for the C2PA Tool and Content Credentials Rust SDK as soon as it becomes available.
  • Implement request throttling or rate limiting on input processing paths to constrain the rate at which resource‑intensive operations can be invoked.
  • Configure monitoring and alerting to detect abnormal spikes in CPU or memory usage, and enforce automatic restart or shutdown policies for the service when thresholds are exceeded.

Generated by OpenCVE AI on August 25, 2026 at 19:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Description CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.
Title CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-25T17:31:27.069Z

Reserved: 2026-08-05T23:51:57.377Z

Link: CVE-2026-71360

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T18:18:00.163

Modified: 2026-08-25T18:18:00.163

Link: CVE-2026-71360

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T19:15:05Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption