


Perceptive Security
SOC/SIEM Consultancy

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() …
Published:
31 juli 2026 om 00:00:00
Alert date:
31 juli 2026 om 22:02:34
Source:
nvd.nist.gov
Web Technologies
Thumbor, an open-source photo thumbnail service by globo.com, contains an HMAC validation bypass vulnerability prior to version 7.8.0. The flaw arises from the use of Python's .replace() method, which removes all occurrences of a substring when stripping the signature from a URL before validation. An attacker can exploit this by inserting the same signature multiple times in the URL, causing the validated string to differ from the actual requested resource. This manipulation allows loading images from unintended domains or paths, effectively bypassing security controls. The vulnerability enables crafting malicious URLs that pass HMAC signature validation while pointing to unauthorized resources. The issue has been patched and fully resolved in Thumbor version 7.8.0. Users are strongly advised to upgrade to the latest version to mitigate this risk.
Technical details
Mitigation steps:
Affected products:
Thumbor
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-53501
https://github.com/thumbor/thumbor/commit/e3ae3e2500537b4d735df4144129a649374bb70b
https://github.com/thumbor/thumbor/releases/tag/7.8.0
https://github.com/thumbor/thumbor/security/advisories/GHSA-mw3h-qjxj-6xg9
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
