globo.com vulnerabilities
6 CVEs tracked
The vendor 'globo.com' appears in our reporting only in the context of its open-source Thumbor photo thumbnail service. The focus is on a cluster of critical vulnerabilities found in Thumbor prior to version 7.8.0. Defenders should immediately upgrade Thumbor to version 7.8.0, as the mentioned flaws enable serious issues including HMAC signature bypass (CVE-2026-53501), path traversal (CVE-2026-53502), ReDoS (CVE-2026-53504), resource exhaustion (CVE-2026-53505), and allowlist bypass (CVE-2026-53500).
Azərbaycanca: Vendor 'globo.com' hesabatlarımızda yalnız özünün açıq mənbəli Thumbor foto miniatür xidməti kontekstində görünür. Bütün diqqət, 7.8.0 versiyasından əvvəlki Thumbor məhsulunda aşkarlanmış kritik zəifliklər toplusuna yönəlib. Müdafiəçilər dərhal Thumbor-u 7.8.0 versiyasına yeniləməlidir, çünki qeyd olunan zəifliklər HMAC imza bypassı (CVE-2026-53501), path traversal (CVE-2026-53502), ReDoS (CVE-2026-53504), resurs tükənməsi (CVE-2026-53505) və icazə siyahısından yan keçmə (CVE-2026-53500) kimi ciddi problemlərə yol açır.
This vendor's CVEs6
This hub is built from skopnix's own reporting on globo.com: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.