top of page
perceptive_background_267k.jpg

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on c…

Published:

30 juli 2026 om 22:00:00

Alert date:

31 juli 2026 om 20:02:34

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Supply Chain & Dependencies

CVE-2026-53504 affects Thumbor, an open-source photo thumbnail service developed by globo.com. The vulnerability exists in the convolution filter's regular expression, which is susceptible to exponential backtracking when processing crafted repeated numeric input. An attacker can exploit this by sending a specially crafted URL request that causes the service to exhaust processing time, resulting in a denial of service condition. This is classified as a ReDoS (Regular Expression Denial of Service) vulnerability. The issue affects all versions of Thumbor prior to 7.8.0. The fix was introduced in version 7.8.0, which patches the problematic regular expression. Users are strongly advised to upgrade to version 7.8.0 or later to mitigate this risk.

Technical details

Mitigation steps:

Affected products:

Thumbor (prior to 7.8.0)

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page