Thumbor is an open-source photo thumbnail service by globo.com. CVE-2026-53505 is a HIGH-rated vulnerability with a CVSS score of 7.5. The filters:proportion(<value>) filter does not enforce an upper bound on <value> and runs in the post-transform phase. An attacker can trigger extremely large resizes (CPU/memory exhaustion) and cause denial of service. This issue is fixed in 7.8.0. Affected systems may f [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T19:17:09.920Z and has not been modified since then. CVE-2026-53504 is a high-severity vulnerability in Thumbor, an open-source photo thumbnail service. The convolution filter regular expression performs exponential backtracking on crafted repeated numeric input, allowing a URL request to exhaust [truncated]
The CVE record for CVE-2026-53502 was published on 2026-07-31T19:17:09.577Z and has not been modified since then. Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes percent-encoded path segments after its root-boundary validation, allowing traversal outside FILE_LOADER_ROOT_PATH through watermark or frame filter input. This issue is fixed in 7.8.0. Users of [truncated]
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() when removing the signature from the URL before validation. Since .replace() removes all occurrences of the substring, an attacker can insert the same signature multiple times in the URL and manipulate the final URL used for validation. This allows [truncated]
Thumbor is an open-source photo thumbnail service by globo.com. CVE-2026-53500 is a HIGH severity vulnerability. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots, allowing hostnames differing at dot positions to match the allowlist. This issue is fixed in 7.8.0. Users should verify their version and apply patches promptly to mitigate the risk of ex [truncated]