THREAT OPS › Threat News › [GHSA] GHSA-6x26-6r6f-m537 (high) — Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot
[GHSA] GHSA-6x26-6r6f-m537 (high) — Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot
GHSA-6x26-6r6f-m537 Severity: high CVE: CVE-2026-53500
Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot
## Summary
The `ALLOWED_SOURCES` configuration is meant to restrict which hosts Thumbor's HTTP loader may fetch images from. Plain-string entries in that list (the overwhelming majority of real-world and documented configurations) ar
Indicators of compromise
- CVE-2026-53500cve
- s.glbimg.comdomain
- saglbimg.comdomain
Original source: https://github.com/advisories/GHSA-6x26-6r6f-m537