Guard
Security
CVEs
CVE 2026 53500 thumbor treats allowed sources string patterns as unescaped regex allowing hostname bypass via w
Guard
Security
CVEs
CVE 2026 53500 thumbor treats allowed sources string patterns as unescaped regex allowing hostname bypass via w
HOL
Overview
Features
Harnesses
Security
Install
Pricing
Enterprise
Affiliates
Docs
Open App
Account
Account
HOL
Overview
Features
Harnesses
Security
Install
Pricing
Enterprise
Affiliates
Docs
Open App
Account
Account
Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot (CVE-2026-53500) | HOL Guard CVE