CVE-2026-34712: CAI Content Credentials | Improper Input Validation (CWE-20)
CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Input Validation vulnerability. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
c2pa-web@0.7.1from your environment.Uninstall c2pa-web@0.7.1 (and earlier versions) if it is not required; avoid running this affected version until a fix is available.
- Remove
Remove
c2pa-v0.80.1from your environment.Uninstall c2pa-v0.80.1 (and earlier versions) if it is not required; avoid running this affected version until a fix is available.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34712?
CVE-2026-34712 has a high severity rating of 7.5.
What kind of vulnerability is CVE-2026-34712?
CVE-2026-34712 is classified as an Improper Input Validation vulnerability.
How do I fix CVE-2026-34712?
To fix CVE-2026-34712, upgrade to CAI Content Credentials versions later than c2pa-web@0.7.1 and c2pa-v0.80.1.
What impact does CVE-2026-34712 have on applications?
Exploitation of CVE-2026-34712 can lead to a denial-of-service condition by crashing the application.
Is user interaction required to exploit CVE-2026-34712?
No, exploitation of CVE-2026-34712 does not require user interaction.