What is CVE-2026-53504?
CVE-2026-53504 is a vulnerability in the open-source Thumbor photo thumbnail service prior to version 7.8.0, caused by exponential backtracking in the convolution filter's regular expression on crafted input. A specially crafted URL request can exhaust processing time, and updating to version 7.8.0 fixes this issue.
Azərbaycanca: CVE-2026-53504, Thumbor açıq mənbəli şəkil thumbnail xidmətinin 7.8.0 versiyasından əvvəlki versiyalarında `convolution` filterində exponential backtracking zəifliyidir. Xüsusi hazırlanmış URL sorğuları vasitəsilə bu zəiflik sistem resurslarını tükədə bilər və problemi aradan qaldırmaq üçün 7.8.0 versiyasına yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: globo.com
FAQ2
What is CVE-2026-53504?
It is an exponential backtracking vulnerability in the open-source Thumbor photo thumbnail service prior to version 7.8.0. The vulnerability exists in the `convolution` filter on crafted input.
How can CVE-2026-53504 be fixed?
To fix this vulnerability, update the Thumbor service to version 7.8.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.