CVE-2026-34671

CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:adobe:c2pa:*:*:*:*:*:rust:*:*
cpe:2.3:a:adobe:c2pa-web:*:*:*:*:*:node.js:*:*

History

09 Jun 2026, 22:16

Type Values Removed Values Added
Summary (en) CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction. (en) CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

15 May 2026, 14:13

Type Values Removed Values Added
First Time Adobe
Adobe c2pa
Adobe c2pa-web
References () https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-53.html - () https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-53.html - Vendor Advisory
CPE cpe:2.3:a:adobe:c2pa:*:*:*:*:*:rust:*:*
cpe:2.3:a:adobe:c2pa-web:*:*:*:*:*:node.js:*:*

12 May 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-12 20:16

Updated : 2026-06-17 10:39


NVD link : CVE-2026-34671

Mitre link : CVE-2026-34671

CVE.ORG link : CVE-2026-34671


JSON object : View

Products Affected

adobe

  • c2pa-web
  • c2pa
CWE
CWE-190

Integer Overflow or Wraparound