CVE-2026-47905: Adobe c2pa

Medium severity, CVSS 6.2. EPSS: 0.3% chance of exploitation in the next 30 days.

CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.

Affected products

  • Adobe c2pa: up to and including 0.80.1
  • Adobe c2pa-Web: up to and including 0.7.1

Published 2026-06-09. Last modified 2026-08-28.