What is CVE-2026-53503?
The vulnerability in Thumbor's `convolution` filter allows user-controlled `columns` parameter to be used as a divisor in the C extension, leading to potential division-by-zero crashes and Denial of Service. All versions prior to 7.8.0 are affected, and immediate update to the patched version is recommended.
Azərbaycanca: CVE-2026-53503: Thumbor-un açıq mənbəli şəkil kiçiltmə xidmətində "convolution" filterində istifadəçi tərəfindən idarə olunan "columns" parametri C genişlənməsində bölən kimi istifadə olunur. Bu, sıfıra bölmə nəticəsində xidmətin dayanmasına (Denial of Service) səbəb ola bilər. 7.8.0 versiyasından əvvəlki bütün versiyalar təsirlənir, dərhal yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: globo.com
FAQ2
How does CVE-2026-53503 affect Thumbor?
The vulnerability allows the `columns` parameter in the `convolution` filter to be used as a divisor in the C extension, leading to division-by-zero crashes and Denial of Service.
Which version of Thumbor should be updated to in order to protect against CVE-2026-53503?
All versions prior to 7.8.0 are affected, so immediate update to version 7.8.0 or later is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.