A vulnerability was found in globo.com Thumbor up to 7.7.0. It has been rated as critical. This impacts the function re.match of the component Allowed Sources. Performing a manipulation of the argument ALLOWED_SOURCES results in incorrect regular expression.

This vulnerability is cataloged as CVE-2026-53500. It is possible to initiate the attack remotely. There is no exploit available.

Upgrading the affected component is advised.