thumbor
PyPI6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting thumborpage 1 of 1
- CVE-2026-53500HIGHCVSS 8.2EG 8.2✓ Fixed in 7.8.02026-07-31
vulnerable: 4.1.3 ... 7.7.7 (118 versions)
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots, so a hostname differing at dot positions can match the allowlist. T…
- CVE-2026-53501HIGHCVSS 8.2EG 8.2✓ Fixed in 7.8.02026-07-31
vulnerable: 4.1.3 ... 7.7.7 (118 versions)
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() when removing the signature from the URL before validation. Since .replace(…
- CVE-2026-53502HIGHCVSS 8.7EG 8.7✓ Fixed in 7.8.02026-07-31
vulnerable: 4.1.3 ... 7.7.7 (118 versions)
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes percent-encoded path segments after its root-boundary validation, allowing traversal outside FILE_LOADER_ROOT_PATH through watermark or fra…
- CVE-2026-53503HIGHCVSS 7.5EG 7.5✓ Fixed in 7.8.02026-07-31
vulnerable: 4.1.3 ... 7.7.7 (118 versions)
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(<matrix>, <columns>, <should_normalize>) filter passes the user-controlled <columns> value to a C extension (thumbor/ext/filters/…
- CVE-2026-53504HIGHCVSS 7.5EG 7.5✓ Fixed in 7.8.02026-07-31
vulnerable: 4.1.3 ... 7.7.7 (118 versions)
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on crafted repeated numeric input, allowing a URL request to exhaust processing tim…
- CVE-2026-53505HIGHCVSS 7.5EG 7.5✓ Fixed in 7.8.02026-07-31
vulnerable: 4.1.3 ... 7.7.7 (118 versions)
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:proportion(<value>) filter does not enforce an upper bound on <value> and runs in the post-transform phase. An attacker can trigger extremely…
Check whether thumbor is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for thumbor CVEs against the assets you own.
Start Free Scan →