Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5vjc-7cxw-4w6j

Опубликовано: 31 июл. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Thumbor has Regex Denial of Service (ReDoS) in convolution filter

Summary

The regular expression used to parse the convolution filter exhibits exponential-time backtracking for certain inputs, enabling a Regular Expression Denial of Service (ReDoS).

Details

The RegExp for convolution is defined as convolution\((?:\s*((?:[-]?[\d]+\.?[\d]*[;])*(?:[-]?[\d]+\.?[\d]*))\s*)(?:,\s*([\d]+)\s*)(?:,\s*([Tt]rue|[Ff]alse|1|0)\s*)?\). Within this expression a dangerous subpattern effectively behaves like (\d+)*,\d+.

PoC

A filter string containing many repeated values will exhaust re.match:

The evaluation occurs on https://github.com/thumbor/thumbor/blob/master/thumbor/filters/__init__.py#L189.

Impact

A specially crafted URL will lead to denial of service, as new images won't be processed until re.match returns.

Пакеты

Наименование

thumbor

pip
Затронутые версииВерсия исправления

<= 7.7.7

7.8.0

EPSS

Процентиль: 26%
0.00335
Низкий

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
ubuntu
8 дней назад

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on crafted repeated numeric input, allowing a URL request to exhaust processing time. This issue is fixed in 7.8.0.

CVSS3: 7.5
nvd
8 дней назад

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on crafted repeated numeric input, allowing a URL request to exhaust processing time. This issue is fixed in 7.8.0.

CVSS3: 7.5
debian
8 дней назад

Thumbor is an open-source photo thumbnail service by globo.com. Prior ...

EPSS

Процентиль: 26%
0.00335
Низкий

7.5 High

CVSS3

Дефекты

CWE-400