CVE-2026-47902: CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)
CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
c2pa-webfrom your environment.If c2pa-web is not required, uninstall/remove the package from affected systems until a fixed version is made available.
- Remove
Remove
c2pa-vfrom your environment.If c2pa-v is not required, uninstall/remove the package from affected systems until a fixed version is made available.
- Configuration
Configure resource limits (CPU and memory) and limits on concurrent requests/connections for processes or containers running the affected components to reduce risk of resource exhaustion.
Hosting/container runtime or process supervisor CPU/memory limits and max concurrent requests/connections = Apply limits - Compensating control
Deploy external mitigations such as rate limiting, request throttling, WAF rules, and network access restrictions (restrict access to trusted IPs/networks) in front of the affected services to reduce the ability of an attacker to exhaust resources.
- Operational
Monitor resource usage and service logs for signs of abnormal consumption; if excessive usage is detected, isolate affected hosts/services and investigate. Maintain alerts for high CPU, memory, and connection counts while a permanent fix is pending.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47902?
The severity of CVE-2026-47902 is medium with a score of 6.2.
What type of vulnerability is identified in CVE-2026-47902?
CVE-2026-47902 is identified as an Uncontrolled Resource Consumption vulnerability classified under CWE-400.
How can I fix CVE-2026-47902?
To fix CVE-2026-47902, upgrade to versions c2pa-web@0.7.2 or c2pa-v0.80.2 or later.
What impact does CVE-2026-47902 have if exploited?
If exploited, CVE-2026-47902 can lead to resource exhaustion, resulting in a denial-of-service condition.
Which versions of CAI Content Credentials are affected by CVE-2026-47902?
CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by CVE-2026-47902.