🛡️ CVE-2026-53500 — thumbor

🟠 CVSS 8.2 — High ✅ No Known Exploit CWE-1333 NVD
8.2
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot

Summary

The ALLOWED_SOURCES configuration is meant to restrict which hosts Thumbor's HTTP loader may fetch images from. Plain-string entries in that list (the overwhelming majority of real-world and documented configurations) are passed directly to re.match() without escaping. Because . is a regex wildcard, every dot in a domain name becomes a bypass vector: s.glbimg.com silently matches sXglbimgYcom, sAglbimg.com, and any other hostname that differs only at a dot position. This undermines the primary SSRF defence that ALLOWED_SOURCES is intended to provide.

Affected component

thumbor/loaders/http_loader.pyvalidate()

Proof of concept

```python

import re

from thumbor.config import Config

from thumbor.context import Context

from thumbor.loaders import http_loader as loader

config = Config()

config.ALLOWED_SOURCES = ["s.glbimg.com"] # typical user config

ctx = Context(None, config, None)

# These should be blocked — both return True due to the unescaped dot

print(loader.validate(ctx, "http://sXglbimgYcom/secret.jpg")) # True ← bypass

print(loader.validate(ctx, "http://sAglbimg.com/secret.jpg")) # True ← bypass

# Legitimate origin — correctly allowed

print(loader.validate(ctx, "http://s.glbimg.com/logo.jpg")) # True ← correct

```

Root cause

thumbor/loaders/http_loader.py (before fix):

```python

for pattern in context.config.ALLOWED_SOURCES:

if isinstance(pattern, Pattern):

match = url

else:

pattern = f"^{pattern}$" # <-- dots not escaped, act as regex wildcard

match = res.hostname

if re.match(pattern, match):

return True

```

Impact

An attacker who can influence the image source URL passed to Thumbor can fetch images from arbitrary hosts, bypassing the ALLOWED_SOURCES allowlist.

Preconditions:

  • ALLOWED_SOURCES contains at least one plain-string entry (the common case; all official documentation examples use plain strings).
  • The attacker can supply or influence the image URL — true whenever ALLOW_UNSAFE_URL = True (the default), or when the application forwards user input to a signed URL endpoint.

Fix

Apply re.escape() to plain-string patterns before compiling them, so every

character is matched literally:

```python

else:

pattern = f"^{re.escape(pattern)}$" # dots and other metacharacters are now literal

match = res.hostname

```

This is a one-call addition with no breaking change for correctly written configurations. Users who need real regular-expression behaviour should supply a compiled pattern (re.compile(r"s\.glbimg\.com")), which is already handled by the existing isinstance(pattern, Pattern) branch and is unaffected by this change.

The ALLOWED_SOURCES docstring in config.py was also updated to document the two-mode behaviour explicitly.

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality high, integrity none, availability low.

Weakness class

CVE-2026-53500 is classified as CWE-1333: Inefficient Regular Expression Complexity. A regular expression backtracks catastrophically on crafted input, consuming CPU out of proportion to input size.

Affected software

CVE-2026-53500 is recorded against 2 packages.

  • thumbor (fixed in 7.8.0)
  • unknown

Timeline and source

Published on 31 July 2026 and last revised on 4 August 2026. No public exploit is currently recorded for this entry. Record sourced from NVD.

References

github.com (Web)
github.com (Web)
github.com (Package)
github.com (Web)

Details

Severity HIGH
CVSS Score 8.2
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
CWE CWE-1333
Public Exploit ✅ No
Source NVD
Published 2026-07-31
Updated 2026-08-12
Modified 2026-08-04
Fix URL N/A

Affected Packages

Software From version Fixed in
thumbor 7.8.0
unknown

Site Security Check

Is thumbor part of your stack?

CVE-2026-53500 is rated CVSS 8.2 High. BotEraser scans your installation against known CVE records and tells you whether this vulnerability applies to the versions you actually run.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.