PYSEC-2026-3616
Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter
Quick fix
PYSEC-2026-3616 — thumbor: upgrade to the fixed version with the command below.
pip install --upgrade 'thumbor>=7.8.0'Details
### Summary The regular expression used to parse the `convolution` filter exhibits exponential-time backtracking for certain inputs, enabling a Regular Expression Denial of Service (ReDoS).
### Details The RegExp for `convolution` is defined as `convolution\((?:\s*((?:[-]?[\d]+\.?[\d]*[;])*(?:[-]?[\d]+\.?[\d]*))\s*)(?:,\s*([\d]+)\s*)(?:,\s*([Tt]rue|[Ff]alse|1|0)\s*)?\)`. Within this expression a dangerous subpattern effectively behaves like `(\d+)*,\d+`.
### PoC A filter string containing many repeated values will exhaust `re.match`: - `convolution(-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11)` - http://localhost:8888/unsafe/0x0/smart/filters:convolution(-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11;-11)/x.png
The evaluation occurs on https://github.com/thumbor/thumbor/blob/master/thumbor/filters/__init__.py#L189.
### Impact A specially crafted URL will lead to denial of service, as new images won't be processed until `re.match` returns.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/thumbor/thumbor/security/advisories/GHSA-5vjc-7cxw-4w6j[WEB]
- https://github.com/thumbor/thumbor/commit/3f38fe1610d20168e91f76d432212de30727eb2e[WEB]
- https://github.com/thumbor/thumbor[PACKAGE]
- https://github.com/thumbor/thumbor/releases/tag/7.8.0[WEB]
- https://pypi.org/project/thumbor[PACKAGE]
- https://github.com/advisories/GHSA-5vjc-7cxw-4w6j[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-53504[ADVISORY]