CVE-2026-34711: CAI Content Credentials | Integer Overflow or Wraparound (CWE-190)
CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
c2pa-web@0.7.1from your environment.Uninstall or remove c2pa-web@0.7.1 from deployments. This version is affected by an integer overflow/wraparound vulnerability that can be exploited to crash the application (denial-of-service). Do not use this version.
- Remove
Remove
c2pa-v0.80.1from your environment.Uninstall or remove c2pa-v0.80.1 from deployments. This version is affected by an integer overflow/wraparound vulnerability that can be exploited to crash the application (denial-of-service). Do not use this version.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34711?
The severity of CVE-2026-34711 is rated high with a score of 7.5.
What impact does CVE-2026-34711 have on affected systems?
CVE-2026-34711 could lead to a denial-of-service condition by crashing the application.
Which versions are affected by CVE-2026-34711?
CVE-2026-34711 affects CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier.
How can I fix CVE-2026-34711?
To fix CVE-2026-34711, upgrade to a version of CAI Content Credentials that is newer than c2pa-web@0.7.1 or c2pa-v0.80.1.
Is user interaction required to exploit CVE-2026-34711?
No, exploitation of CVE-2026-34711 does not require user interaction.