CVE-2026-33205 PUBLISHED

calibre has Server-Side Request Forgery in ebook viewer backend

Assigner: GitHub_M
Reserved: 17.03.2026 Published: 27.03.2026 Updated: 27.03.2026

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a Server-Side Request Forgery vulnerability in the background-image endpoint of calibre e-book reader's web view allows an attacker to perform blind GET requests to arbitrary URLs and exfiltrate information out from the ebook sandbox. Version 9.6.0 patches the issue.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 4.8

Product Status

Vendor kovidgoyal
Product calibre
Versions
  • Version < 9.6.0 is affected

References

Problem Types

  • CWE-918: Server-Side Request Forgery (SSRF) CWE