Browse all 6 CVE security advisories affecting thumbor. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-53502 | Thumbor has path traversal via post-validation URL decoding bypass in file_loader — thumborCWE-22 | 8.7 | High | 2026-07-31 |
| CVE-2026-53505 | Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS — thumborCWE-400 | 7.5 | High | 2026-07-31 |
| CVE-2026-53504 | Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter — thumborCWE-400 | 7.5 | High | 2026-07-31 |
| CVE-2026-53503 | Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS — thumborCWE-20 | 7.5 | High | 2026-07-31 |
| CVE-2026-53501 | Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature — thumborCWE-347 | 8.2 | High | 2026-07-31 |
| CVE-2026-53500 | Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot — thumborCWE-918 | 8.2 | High | 2026-07-31 |
This page lists every published CVE security advisory associated with thumbor. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.