CVE-2026-47904: CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)
CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
c2pa-webfrom your environment.Uninstall or remove the affected CAI Content Credentials package c2pa-web (versions up to and including 0.7.1) from deployments if it is not required, or take it out of service until a patched release is available.
- Remove
Remove
c2pa-vfrom your environment.Uninstall or remove the affected CAI Content Credentials package c2pa-v (versions up to and including 0.80.1) from deployments if it is not required, or take it out of service until a patched release is available.
- Compensating control
Until a fixed version is available and applied, implement mitigations to reduce the risk of resource exhaustion: apply rate limiting and request throttling, enforce connection and request quotas, and configure resource limits (CPU/memory) or WAF rules to limit impact from abusive requests.
- Operational
Monitor application and infrastructure metrics (CPU, memory, request rates, error rates) and logs for indicators of resource exhaustion or denial-of-service; have procedures to throttle, block, or restart affected services to restore availability while awaiting a patch.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47904?
The severity of CVE-2026-47904 is rated as medium with a score of 6.2.
How do I fix CVE-2026-47904?
To fix CVE-2026-47904, update to the latest version of CAI Content Credentials that addresses the uncontrolled resource consumption vulnerability.
What are the potential impacts of CVE-2026-47904?
The potential impacts of CVE-2026-47904 include exhausting system resources and causing an application denial-of-service condition.
Which versions are affected by CVE-2026-47904?
CVE-2026-47904 affects CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier.
What types of attacks are possible with CVE-2026-47904?
An attacker can exploit CVE-2026-47904 to perform denial-of-service attacks by consuming system resources.