-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4705-1                [email protected]
https://www.debian.org/lts/security/                          Abhijith PA
July 29, 2026                                 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : calibre
Version        : 5.12.0+dfsg-1+deb11u5
CVE ID         : CVE-2026-27810 CVE-2026-27824 CVE-2026-30853 CVE-2026-33205 
                 CVE-2026-33206

Multiple vulnerabilities have been discovered in calibre, an e-book
manager.

CVE-2026-27810

    An HTTP Response Header Injection vulnerability in the calibre
    Content Server allows any authenticated user to inject arbitrary
    HTTP headers into server responses via an unsanitized
    `content_disposition` query parameter in the `/get/` and
    `/data-files/get/` endpoints

CVE-2026-27824

    The calibre Content Server's brute-force protection mechanism uses
    a ban key derived from both `remote_addr` and the
    `X-Forwarded-For` header. Since the `X-Forwarded-For` header is
    read directly from the HTTP request without any validation or
    trusted-proxy configuration, an attacker can bypass IP-based bans
    by simply changing or adding this header, rendering the
    brute-force protection completely ineffective. This is
    particularly dangerous for calibre servers exposed to the
    internet, where brute-force protection is the primary defense
    against credential stuffing and password guessing attacks.

CVE-2026-30853

    A path traversal vulnerability in the RocketBook (.rb) input
    plugin (src/calibre/ebooks/rb/reader.py) allows an attacker to
    write arbitrary files to any path writable by the calibre process
    when a user opens or converts a crafted .rb file.

CVE-2026-33205

    A Server-Side Request Forgery vulnerability in the
    background-image endpoint of calibre e-book reader's web view
    allows an attacker to perform blind GET requests to arbitrary URLs
    and exfiltrate information out from the ebook sandbox.

CVE-2026-33206

    A path traversal vulnerability exists in Calibre' handling of
    images in Markdown and other similar text-based files allowing an
    attacker to include arbitrary files from the file system into the
    converted book. Additionally, missing authentication and
    server-side request forgery in the background-image endpoint in the
    ebook reader web view allow the files to be exfiltrated without
    additional interaction.

For Debian 11 bullseye, these problems have been fixed in version
5.12.0+dfsg-1+deb11u5.

We recommend that you upgrade your calibre packages.

For the detailed security status of calibre please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/calibre

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAmppujIACgkQhj1N8u2c
KO+HhBAAg2hZXdE7ZsaSQQKCExlvxaV6kQMCZqI5ftxdAW1kd5owSdPdXwq0uQSm
pBAVgTCG25pYJN5dWWOI8oJHw1p5kB6ZSP3ZLVbS+mX0Eds/WbLeshSi6E3dRdQk
WE83hVe9mP5ZJ9ywqtvPVkLm4O2INdtUIas9tKgJCDmQmSAKihfzWQhXErjgtgrX
46TDBfwXTd782plp/wBaVXrybzS5fpJw3hWX5SPNPdYQIU5aDC0onz/FMbQZjJ0G
ib5Rt5C/hf/1ynDBGdw7F9KH2sEh7EGmGGIbeZewmcka2/Bz7n1T6mEAEfWijOC7
Q3M0i7J4L2ssScqPjomg0b8f4IHarqbD+DGssY8nOkHc7G2DNj2A8A0hFcIbc/7V
DpOgiVrd3WdFKCIIByxS2sgSbxCWv8L2bk9nHHOon1f63dntYaoqlz+tk03pDTW4
2twTn0+TDeSlMXFXjtZ/XSg2kP0SK8LvRPv38+rrRuUTa/IXMsMukDXQ3mYqTBhE
Ode4/ZEyIw4jm7MjYctnOOUWL/hqOPdCxfMAplV4NfZOAxtDbgjzsLOkJiVHy3t7
b/+cCtGygKQR7fBg4jWv+Mhe+MtNWry4mKFgxY/3hWX2EA6luosRGwTURqlH+Pl9
GGqSzRHMk5cqLfeyWiTtfKEQSapYImZ4OP/OGZpHW6AttwZhxnY=
=DTbr
-----END PGP SIGNATURE-----

Reply via email to