


Perceptive Security
SOC/SIEM Consultancy

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on c…
Published:
30 juli 2026 om 22:00:00
Alert date:
31 juli 2026 om 20:02:34
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies
CVE-2026-53504 affects Thumbor, an open-source photo thumbnail service developed by globo.com. The vulnerability exists in the convolution filter's regular expression, which is susceptible to exponential backtracking when processing crafted repeated numeric input. An attacker can exploit this by sending a specially crafted URL request that causes the service to exhaust processing time, resulting in a denial of service condition. This is classified as a ReDoS (Regular Expression Denial of Service) vulnerability. The issue affects all versions of Thumbor prior to 7.8.0. The fix was introduced in version 7.8.0, which patches the problematic regular expression. Users are strongly advised to upgrade to version 7.8.0 or later to mitigate this risk.
Technical details
Mitigation steps:
Affected products:
Thumbor (prior to 7.8.0)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-53504
https://github.com/thumbor/thumbor/commit/3f38fe1610d20168e91f76d432212de30727eb2e
https://github.com/thumbor/thumbor/releases/tag/7.8.0
https://github.com/thumbor/thumbor/security/advisories/GHSA-5vjc-7cxw-4w6j
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
