Improper Verification of Cryptographic Signature Affecting thumbor package, versions [,7.8.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.21% (12th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-THUMBOR-18507989
  • published2 Aug 2026
  • disclosed31 Jul 2026
  • creditUnknown

Introduced: 31 Jul 2026

NewCVE-2026-53501  (opens in a new tab)
CWE-347  (opens in a new tab)

How to fix?

Upgrade thumbor to version 7.8.0 or higher.

Overview

thumbor is a thumbor is an open-source photo thumbnail service by globo.com

Affected versions of this package are vulnerable to Improper Verification of Cryptographic Signature via the URL signature removal process. An attacker can manipulate the validated URL and bypass intended access controls by injecting additional signature substrings into the request path, resulting in the loading of resources from unauthorized domains or paths.

CVSS Base Scores

version 4.0
version 3.1