CVE-2026-53501
Last modified
CVE-2026-53501 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() when removing the signature from the URL before validation.
Description
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() when removing the signature from the URL before validation. Since .replace() removes all occurrences of the substring, an attacker can insert the same signature multiple times in the URL and manipulate the final URL used for validation. This allows crafting URLs where the validated string differs from the actual requested resource, enabling loading images from unintended domains or paths. This issue is fixed in 7.8.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| thumbor | thumbor | < 7.8.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-53501?
How severe is CVE-2026-53501?
How do I fix CVE-2026-53501?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-53488containerd is an open-source container runtime. In versions …8.8
- CVE-2026-53489containerd is an open-source container runtime. Versions pri…6.5
- CVE-2026-5349A vulnerability was identified in Trendnet TEW-657BRM 1.00.1…8.8
- CVE-2026-53492containerd is an open-source container runtime. In Versions …9.6
- CVE-2026-5350A security flaw has been discovered in Trendnet TEW-657BRM 1…8.8
- CVE-2026-53500Thumbor is an open-source photo thumbnail service by globo.c…8.2
- CVE-2026-53502Thumbor is an open-source photo thumbnail service by globo.c…8.7
- CVE-2026-53503Thumbor is an open-source photo thumbnail service by globo.c…7.5
- CVE-2026-53504Thumbor is an open-source photo thumbnail service by globo.c…7.5
- CVE-2026-53505Thumbor is an open-source photo thumbnail service by globo.c…7.5
- CVE-2026-5351A weakness has been identified in Trendnet TEW-657BRM 1.00.1…8.8
- CVE-2026-53510Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon:…8.1
Are you affected by CVE-2026-53501?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
