THREAT OPS › Threat News › [GHSA] GHSA-5vjc-7cxw-4w6j (high) — Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter
[GHSA] GHSA-5vjc-7cxw-4w6j (high) — Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter
GHSA-5vjc-7cxw-4w6j Severity: high CVE: CVE-2026-53504
Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter
### Summary The regular expression used to parse the `convolution` filter exhibits exponential-time backtracking for certain inputs, enabling a Regular Expression Denial of Service (ReDoS).
### Details The RegExp for `convolution` is defined as `convolution\((?:\s*((?:[-]?[
Indicators of compromise
- CVE-2026-53504cve
Original source: https://github.com/advisories/GHSA-5vjc-7cxw-4w6j