CVE-2026-34712: CAI Content Credentials | Improper Input Validation (CWE-20)
Published Jun 9, 2026
·Updated
CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Input Validation vulnerability. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Affected Software
4 affected components
npm/c2pa-web<=0.7.1
npm/c2pa-v<=0.80.1
Adobe C2pa Rust<=0.80.1
Adobe C2pa-web Node.js<=0.7.1
Event History
Jun 9, 2026
CVE Published
via MITRE·09:21 PM
Data Sourced
via MITRE·09:21 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-34712?
CVE-2026-34712 has a high severity rating of 7.5.
2
What kind of vulnerability is CVE-2026-34712?
CVE-2026-34712 is classified as an Improper Input Validation vulnerability.
3
How do I fix CVE-2026-34712?
To fix CVE-2026-34712, upgrade to CAI Content Credentials versions later than c2pa-web@0.7.1 and c2pa-v0.80.1.
4
What impact does CVE-2026-34712 have on applications?
Exploitation of CVE-2026-34712 can lead to a denial-of-service condition by crashing the application.
5
Is user interaction required to exploit CVE-2026-34712?
No, exploitation of CVE-2026-34712 does not require user interaction.