CVE-2026-53505

Summary

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:proportion(<value>) filter does not enforce an upper bound on <value> and runs in the post-transform phase. An attacker can trigger extremely large resizes (CPU/memory exhaustion) and cause denial of service. This issue is fixed in 7.8.0.

Affected Software

VendorProductVersion RangeStatus
thumborthumbor< 7.8.0affected

Weaknesses

  • CWE-400: CWE-400: Uncontrolled Resource Consumption

References