CVE-2026-47903: CAI Content Credentials | Improper Input Validation (CWE-20)
CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Input Validation vulnerability. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
c2pa-web@0.7.1from your environment.Uninstall or remove c2pa-web@0.7.1 (and earlier) from affected systems until a patched/fixed release is available.
- Remove
Remove
c2pa-v@0.80.1from your environment.Uninstall or remove c2pa-v@0.80.1 (and earlier) from affected systems until a patched/fixed release is available.
- Compensating control
Apply network-level protections (for example a WAF, input-sanitizing proxy, or firewall rules) to block or sanitize untrusted input to the CAI Content Credentials components or isolate those services from untrusted networks until a fixed release is provided.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47903?
The severity of CVE-2026-47903 is medium with a score of 6.2.
How do I fix CVE-2026-47903?
To fix CVE-2026-47903, upgrade to CAI Content Credentials versions c2pa-web@0.8.0 or later.
What is the impact of CVE-2026-47903?
CVE-2026-47903 can lead to a denial-of-service condition by crashing the application.
What products are affected by CVE-2026-47903?
CVE-2026-47903 affects CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier.
What kind of vulnerability is CVE-2026-47903?
CVE-2026-47903 is an Improper Input Validation vulnerability categorized under CWE-20.