CVE-2026-53505: Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS
Thumbor’s filters:proportion(<value>) filter does not enforce an upper bound on <value> and runs in the post-transform phase. An attacker can trigger extremely large resizes (CPU/memory exhaustion) and cause denial of service.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-53505 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →