What is CVE-2026-53501?
CVE-2026-53501 is a vulnerability in Thumbor prior to version 7.8.0, where HMAC signature validation can be bypassed due to improper use of Python's .replace() method for removing the signature from URLs. An attacker can inject a substring to evade authentication. Affected systems should be updated to version 7.8.0 or later immediately.
Azərbaycanca: CVE-2026-53501 Thumbor-un 7.8.0-dən əvvəlki versiyalarında HMAC imza yoxlamasının Python-un .replace() funksiyası ilə səhv aparılması səbəbindən yan keçmə zəifliyidir. Təcavüzkar URL-ə xüsusi substring əlavə edərək imza doğrulamasını atlaya bilər. Təsirə məruz qalan sistemlərdə dərhal 7.8.0 və ya daha yeni versiyaya yeniləmə aparılmalıdır.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which versions of Thumbor are affected by CVE-2026-53501?
This vulnerability affects Thumbor versions prior to 7.8.0.
What is the root cause of CVE-2026-53501?
The vulnerability is caused by improper HMAC signature validation using Python's .replace() method.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.