thumbor 厂商相关 6 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。
| CVE ID | タイトル | CVSS | 深刻度 | 公開日 |
|---|---|---|---|---|
| CVE-2026-53502 | Thumbor has path traversal via post-validation URL decoding bypass in file_loader — thumborCWE-22 | 8.7 | High | 2026-07-31 |
| CVE-2026-53505 | Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS — thumborCWE-400 | 7.5 | High | 2026-07-31 |
| CVE-2026-53504 | Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter — thumborCWE-400 | 7.5 | High | 2026-07-31 |
| CVE-2026-53503 | Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS — thumborCWE-20 | 7.5 | High | 2026-07-31 |
| CVE-2026-53501 | Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature — thumborCWE-347 | 8.2 | High | 2026-07-31 |
| CVE-2026-53500 | Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot — thumborCWE-918 | 8.2 | High | 2026-07-31 |
本页汇总了 thumbor 厂商截至目前公开的全部 6 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。