Количество 4
Количество 4
CVE-2026-53500
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots, so a hostname differing at dot positions can match the allowlist. This issue is fixed in 7.8.0.
CVE-2026-53500
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots, so a hostname differing at dot positions can match the allowlist. This issue is fixed in 7.8.0.
CVE-2026-53500
Thumbor is an open-source photo thumbnail service by globo.com. Prior ...
GHSA-6x26-6r6f-m537
Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-53500 Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots, so a hostname differing at dot positions can match the allowlist. This issue is fixed in 7.8.0. | CVSS3: 8.2 | 0% Низкий | 8 дней назад | |
CVE-2026-53500 Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots, so a hostname differing at dot positions can match the allowlist. This issue is fixed in 7.8.0. | CVSS3: 8.2 | 0% Низкий | 8 дней назад | |
CVE-2026-53500 Thumbor is an open-source photo thumbnail service by globo.com. Prior ... | CVSS3: 8.2 | 0% Низкий | 8 дней назад | |
GHSA-6x26-6r6f-m537 Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot | CVSS3: 8.2 | 0% Низкий | 8 дней назад |
Уязвимостей на страницу