THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-mw3h-qjxj-6xg9 (high) — Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature

[GHSA] GHSA-mw3h-qjxj-6xg9 (high) — Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature

highgithub_advisoriesPublished 2026-07-31

GHSA-mw3h-qjxj-6xg9 Severity: high CVE: CVE-2026-53501

Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature

# HMAC validation bypass via multiple `.replace()` calls when removing URL signature

## Summary

Thumbor’s HMAC validation can be bypassed due to the use of Python’s `.replace()` when removing the signature from the URL before validation. Since `.re

Indicators of compromise

Original source: https://github.com/advisories/GHSA-mw3h-qjxj-6xg9