THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-6x26-6r6f-m537 (high) — Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot

[GHSA] GHSA-6x26-6r6f-m537 (high) — Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot

highgithub_advisoriesPublished 2026-07-31

GHSA-6x26-6r6f-m537 Severity: high CVE: CVE-2026-53500

Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot

## Summary

The `ALLOWED_SOURCES` configuration is meant to restrict which hosts Thumbor's HTTP loader may fetch images from. Plain-string entries in that list (the overwhelming majority of real-world and documented configurations) ar

Indicators of compromise

Original source: https://github.com/advisories/GHSA-6x26-6r6f-m537