-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4705-1 [email protected]
https://www.debian.org/lts/security/ Abhijith PA
July 29, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------
Package : calibre
Version : 5.12.0+dfsg-1+deb11u5
CVE ID : CVE-2026-27810 CVE-2026-27824 CVE-2026-30853 CVE-2026-33205
CVE-2026-33206
Multiple vulnerabilities have been discovered in calibre, an e-book
manager.
CVE-2026-27810
An HTTP Response Header Injection vulnerability in the calibre
Content Server allows any authenticated user to inject arbitrary
HTTP headers into server responses via an unsanitized
`content_disposition` query parameter in the `/get/` and
`/data-files/get/` endpoints
CVE-2026-27824
The calibre Content Server's brute-force protection mechanism uses
a ban key derived from both `remote_addr` and the
`X-Forwarded-For` header. Since the `X-Forwarded-For` header is
read directly from the HTTP request without any validation or
trusted-proxy configuration, an attacker can bypass IP-based bans
by simply changing or adding this header, rendering the
brute-force protection completely ineffective. This is
particularly dangerous for calibre servers exposed to the
internet, where brute-force protection is the primary defense
against credential stuffing and password guessing attacks.
CVE-2026-30853
A path traversal vulnerability in the RocketBook (.rb) input
plugin (src/calibre/ebooks/rb/reader.py) allows an attacker to
write arbitrary files to any path writable by the calibre process
when a user opens or converts a crafted .rb file.
CVE-2026-33205
A Server-Side Request Forgery vulnerability in the
background-image endpoint of calibre e-book reader's web view
allows an attacker to perform blind GET requests to arbitrary URLs
and exfiltrate information out from the ebook sandbox.
CVE-2026-33206
A path traversal vulnerability exists in Calibre' handling of
images in Markdown and other similar text-based files allowing an
attacker to include arbitrary files from the file system into the
converted book. Additionally, missing authentication and
server-side request forgery in the background-image endpoint in the
ebook reader web view allow the files to be exfiltrated without
additional interaction.
For Debian 11 bullseye, these problems have been fixed in version
5.12.0+dfsg-1+deb11u5.
We recommend that you upgrade your calibre packages.
For the detailed security status of calibre please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/calibre
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAmppujIACgkQhj1N8u2c
KO+HhBAAg2hZXdE7ZsaSQQKCExlvxaV6kQMCZqI5ftxdAW1kd5owSdPdXwq0uQSm
pBAVgTCG25pYJN5dWWOI8oJHw1p5kB6ZSP3ZLVbS+mX0Eds/WbLeshSi6E3dRdQk
WE83hVe9mP5ZJ9ywqtvPVkLm4O2INdtUIas9tKgJCDmQmSAKihfzWQhXErjgtgrX
46TDBfwXTd782plp/wBaVXrybzS5fpJw3hWX5SPNPdYQIU5aDC0onz/FMbQZjJ0G
ib5Rt5C/hf/1ynDBGdw7F9KH2sEh7EGmGGIbeZewmcka2/Bz7n1T6mEAEfWijOC7
Q3M0i7J4L2ssScqPjomg0b8f4IHarqbD+DGssY8nOkHc7G2DNj2A8A0hFcIbc/7V
DpOgiVrd3WdFKCIIByxS2sgSbxCWv8L2bk9nHHOon1f63dntYaoqlz+tk03pDTW4
2twTn0+TDeSlMXFXjtZ/XSg2kP0SK8LvRPv38+rrRuUTa/IXMsMukDXQ3mYqTBhE
Ode4/ZEyIw4jm7MjYctnOOUWL/hqOPdCxfMAplV4NfZOAxtDbgjzsLOkJiVHy3t7
b/+cCtGygKQR7fBg4jWv+Mhe+MtNWry4mKFgxY/3hWX2EA6luosRGwTURqlH+Pl9
GGqSzRHMk5cqLfeyWiTtfKEQSapYImZ4OP/OGZpHW6AttwZhxnY=
=DTbr
-----END PGP SIGNATURE-----