Impact
This vulnerability arises from improper input validation within CAI Content Credentials, allowing an attacker to supply crafted data that causes the application to crash. The resulting denial‑of‑service prevents legitimate users from accessing the service until it is restarted, potentially impacting availability for enterprises relying on content authentication.
Affected Systems
Adobe C2PA Tool and Adobe Content Credentials Rust SDK are the affected products. The issue is cataloged for the relevant Adobe applications that use these components to verify digital content authenticity, but no specific version range is listed in the provided data.
Risk and Exploitability
The CVSS score of 7.5 classifies the vulnerability as high severity. The EPSS score is not available, indicating that up‑to‑date exploitation probability data is lacking. This issue is not yet listed in the CISA KEV catalog. Exploitation does not require user interaction and can be performed remotely by sending malformed input to the vulnerable component. The lack of a publicly known patch or workaround suggests that the risk hinges on whether the affected system is exposed to untrusted data streams.
OpenCVE Enrichment