Denial of Service Vulnerability in Thumbor by Globo.com
CVE-2026-53505
7.5HIGH
What is CVE-2026-53505?
Thumbor, an open-source photo thumbnail service developed by Globo.com, has a flaw in its filters:proportion() filter prior to version 7.8.0. This vulnerability allows an attacker to input an unbounded , leading to excessive resource consumption and potential denial of service. It is crucial for users to upgrade to version 7.8.0 or later to mitigate this risk.
Affected Version(s)
thumbor < 7.8.0
