CVE-2026-53502

Source
https://cve.org/CVERecord?id=CVE-2026-53502
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53502.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-53502
Aliases
Downstream
Published
2026-07-31T19:03:16Z
Modified
2026-09-10T03:30:47Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Thumbor has path traversal via post-validation URL decoding bypass in file_loader
Details

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes percent-encoded path segments after its root-boundary validation, allowing traversal outside FILE_LOADER_ROOT_PATH through watermark or frame filter input. This issue is fixed in 7.8.0.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53502.json"
}
References

Affected packages

Git / github.com/thumbor/thumbor

Affected ranges

Type
GIT
Repo
https://github.com/thumbor/thumbor
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "7.8.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.1.0
0.1.1
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.10
0.7.11
0.7.12
0.7.13
0.7.14
0.7.9
0.8.0
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.3
0.9.4
0.9.5
0.9.6
0.9.7
2.*
2.0.2
2.0.4
2.0.5
2.3.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.8
2.8.0
2.8.1
3.*
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.11.0
3.11.1
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.14.0
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.14.6
3.14.7
3.15.0
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.10
3.6.11
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
3.7.0
3.7.1
3.7.2
3.7.3
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
4.*
4.0.0
4.0.3
4.0.4
4.1.0
4.1.1
4.1.2
4.1.3
4.10.0
4.10.1
4.10.2
4.10.3
4.11.0
4.11.1
4.12.0
4.12.1
4.12.2
4.2.0
4.2.1
4.3.0
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.6.0
4.7.0
4.7.1
4.8.0
4.8.1
4.8.2
4.8.3
4.8.6
4.8.7
4.9.0
4.9.1
5.*
5.0.0
5.0.0-rc1
5.0.0rc2
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.1.0
5.2.0
5.2.1
6.*
6.0.0
6.0.0b1
6.0.0b2
6.0.0b3
6.0.0b5
6.0.1
6.2.0
6.2.1
6.3.0
6.3.1
6.3.2
6.3.3rc
6.4.0
6.4.1
6.4.2
6.4.3
6.5.0
6.5.2
6.6.0
6.6.1
6.7.0
6.7.1
7.*
7.0.0
7.0.0a1
7.0.0a2
7.0.0a3
7.0.0a4
7.0.0a5
7.0.0b1
7.0.1
7.0.10
7.0.11
7.0.12
7.0.2
7.0.3
7.0.5
7.0.6
7.0.7
7.0.8
7.0.9
7.1.0
7.1.1
7.1.2
7.2.0
7.2.1
7.3.0
7.3.1
7.3.2
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.1
7.5.2
7.6.0
7.7.0
7.7.1
7.7.2
7.7.3
7.7.4
7.7.5
7.7.6
7.7.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53502.json"