What is CVE-2026-53505?
CVE-2026-53505 affects the Thumbor open-source photo thumbnail service. Prior to version 7.8.0, the `filters:proportion()` filter lacks an upper bound on its value, allowing attackers to trigger extremely large resizes that cause CPU and memory exhaustion, leading to denial of service. Users should upgrade to the latest version or enforce input value limits.
Azərbaycanca: CVE-2026-53505 Thumbor açıq mənbəli şəkil miniatür xidmətində aşkarlanıb. 7.8.0 versiyasından əvvəlki versiyalarda `filters:proportion()` filtri üçün yuxarı hədd tapılmadığı üçün, təcavüzkar CPU və yaddaş tükənməsinə səbəb olan həddindən artıq böyük ölçü dəyişdirmələrini tetikleyərək denial of service yarada bilər. Thumbor istifadəçiləri ən son versiyaya yenilənməli və ya giriş dəyərlərini məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: globo.com
FAQ2
Which product is affected by CVE-2026-53505?
This vulnerability affects the Thumbor open-source photo thumbnail service.
How can CVE-2026-53505 be mitigated?
Users should upgrade Thumbor to the latest version or enforce input value limits.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.