github thumbor/thumbor 7.8.0
Release 7.8.0

15 days ago

Security

This release includes fixes for multiple privately reported security issues.
Users running thumbor in production are strongly encouraged to upgrade to
7.8.0.

Fixed issues include:

  • file_loader path confinement bypasses that could allow reads outside
    FILE_LOADER_ROOT_PATH in affected configurations.
  • URL signature validation bypass involving repeated or encoded hash prefixes.
  • ALLOWED_SOURCES pattern hardening for string-based source restrictions.
  • Denial of service fixes in the convolution filter.
  • Denial of service fix in the proportion filter.

Security advisories will be published with more details and CVE/GHSA references.

What's Changed

New Contributors

Full Changelog: 7.7.7...7.8.0

Don't miss a new thumbor release

NewReleases is sending notifications on new releases.