Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-53504

Опубликовано: 31 июл. 2026
Источник: debian

Описание

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on crafted repeated numeric input, allowing a URL request to exhaust processing time. This issue is fixed in 7.8.0.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
thumborfixed7.8.0-1package

Примечания

  • https://github.com/thumbor/thumbor/security/advisories/GHSA-5vjc-7cxw-4w6j

  • Fixed by: https://github.com/thumbor/thumbor/commit/3f38fe1610d20168e91f76d432212de30727eb2e (7.8.0)

Связанные уязвимости

CVSS3: 7.5
ubuntu
8 дней назад

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on crafted repeated numeric input, allowing a URL request to exhaust processing time. This issue is fixed in 7.8.0.

CVSS3: 7.5
nvd
8 дней назад

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on crafted repeated numeric input, allowing a URL request to exhaust processing time. This issue is fixed in 7.8.0.

CVSS3: 7.5
github
8 дней назад

Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter