thumbor thumbor是thumbor组织开源的一个图像处理服务。 thumbor 7.8.0之前版本存在路径遍历漏洞,该漏洞源于file_loader在根边界验证后解码百分号编码的路径段,可通过watermark或frame filter输入进行路径遍历,导致访问FILE_LOADER_ROOT_PATH之外的文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-53500 | 8.2 HIGH | Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypas |
| CVE-2026-53501 | 8.2 HIGH | Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signatu |
| CVE-2026-53505 | 7.5 HIGH | Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS |
| CVE-2026-53503 | 7.5 HIGH | Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS |
| CVE-2026-53504 | 7.5 HIGH | Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter |
No comments yet