Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:proportion(<value>) filter does not enforce an upper bound on <value> and runs in the post-transform phase. An attacker can trigger extremely large resizes (CPU/memory exhaustion) and cause denial of service. This issue is fixed in 7.8.0.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-31 19:17
Updated : 2026-09-08 20:51
NVD link : CVE-2026-53505
Mitre link : CVE-2026-53505
CVE.ORG link : CVE-2026-53505
JSON object : View
Products Affected
No product.
CWE
CWE-400
Uncontrolled Resource Consumption
