CVE-2026-53505

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:proportion(<value>) filter does not enforce an upper bound on <value> and runs in the post-transform phase. An attacker can trigger extremely large resizes (CPU/memory exhaustion) and cause denial of service. This issue is fixed in 7.8.0.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-31 19:17

Updated : 2026-09-08 20:51


NVD link : CVE-2026-53505

Mitre link : CVE-2026-53505

CVE.ORG link : CVE-2026-53505


JSON object : View

Products Affected

No product.

CWE
CWE-400

Uncontrolled Resource Consumption