calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a Server-Side Request Forgery vulnerability in the background-image endpoint of calibre e-book reader's web view allows an attacker to perform blind GET requests to arbitrary URLs and exfiltrate information out from the ebook sandbox. Version 9.6.0 patches the issue.
Metrics
Affected Vendors & Products
References
History
Fri, 27 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 27 Mar 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a Server-Side Request Forgery vulnerability in the background-image endpoint of calibre e-book reader's web view allows an attacker to perform blind GET requests to arbitrary URLs and exfiltrate information out from the ebook sandbox. Version 9.6.0 patches the issue. | |
| Title | calibre has Server-Side Request Forgery in ebook viewer backend | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-03-27T13:52:06.860Z
Updated: 2026-03-27T19:58:43.747Z
Reserved: 2026-03-17T23:23:58.312Z
Link: CVE-2026-33205
Updated: 2026-03-27T18:57:56.907Z
Status : Received
Published: 2026-03-27T15:16:54.277
Modified: 2026-03-27T15:16:54.277
Link: CVE-2026-33205
No data.
ReportizFlow