Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-phj3-59pf-cp83 | Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS |
Mon, 03 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 02 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Thumbor
Thumbor thumbor |
|
| Vendors & Products |
Thumbor
Thumbor thumbor |
Fri, 31 Jul 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:proportion(<value>) filter does not enforce an upper bound on <value> and runs in the post-transform phase. An attacker can trigger extremely large resizes (CPU/memory exhaustion) and cause denial of service. This issue is fixed in 7.8.0. | |
| Title | Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-03T17:20:37.186Z
Reserved: 2026-06-09T17:05:25.059Z
Link: CVE-2026-53505
Updated: 2026-08-03T17:20:31.883Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-02T20:32:15Z
Github GHSA