top of page
perceptive_background_267k.jpg

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() …

Published:

30 juli 2026 om 22:00:00

Alert date:

31 juli 2026 om 20:02:34

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies

Thumbor, an open-source photo thumbnail service by globo.com, contains an HMAC validation bypass vulnerability prior to version 7.8.0. The flaw arises from the use of Python's .replace() method, which removes all occurrences of a substring when stripping the signature from a URL before validation. An attacker can exploit this by inserting the same signature multiple times in the URL, causing the validated string to differ from the actual requested resource. This manipulation allows loading images from unintended domains or paths, effectively bypassing security controls. The vulnerability enables crafting malicious URLs that pass HMAC signature validation while pointing to unauthorized resources. The issue has been patched and fully resolved in Thumbor version 7.8.0. Users are strongly advised to upgrade to the latest version to mitigate this risk.

Technical details

Mitigation steps:

Affected products:

Thumbor

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page