CVE-2026-53500

Publication date 31 July 2026

Last updated 7 August 2026


Ubuntu priority

Cvss 3 Severity Score

8.2 · High

Score breakdown

Description

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots, so a hostname differing at dot positions can match the allowlist. This issue is fixed in 7.8.0.

Status

Package Ubuntu Release Status
thumbor 26.04 LTS resolute
Needs evaluation
24.04 LTS noble Not in release
22.04 LTS jammy Not in release

Severity score breakdown

CVSS version: CVSS v3.0

Base score 8.2 · High

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L


Access our resources on patching vulnerabilities