CVE-2026-33205

unknown
Published — · Modified —
CVSS v3
—
CVSS v4 NEW
—
not yet in upstream
VIR risk
—

Description

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a Server-Side Request Forgery vulnerability in the background-image endpoint of calibre e-book reader's web view allows an attacker to perform blind GET requests to arbitrary URLs and exfiltrate information out from the ebook sandbox. Version 9.6.0 patches the issue.

Predictions

Exploit likelihood
20%
Patch ETA
—

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2026-33205 NameCVE-2026-33205 Descriptioncalibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a Server-Side Request Forgery vulnerability in the background-image endpoint of calibre e-book reader's web view allows an attacker to perform blind GET requests to arbitrary URLs and exfiltrate information out from the ebook…

CVE-2026-33205

NameCVE-2026-33205
Descriptioncalibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a Server-Side Request Forgery vulnerability in the background-image endpoint of calibre e-book reader's web view allows an attacker to perform blind GET requests to arbitrary URLs and exfiltrate information out from the ebook sandbox. Version 9.6.0 patches the issue.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
calibre (PTS)bullseye5.12.0+dfsg-1+deb11u2vulnerable
bullseye (security)5.12.0+dfsg-1+deb11u4vulnerable
bookworm6.13.0+repack-2+deb12u6vulnerable
trixie8.5.0+ds-1+deb13u2vulnerable
forky, sid9.8.0+ds+~0.10.6-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
calibresource(unstable)9.6.0+ds+~0.10.5-1

Notes

[trixie] - calibre <no-dsa> (Minor issue)
[bookworm] - calibre <no-dsa> (Minor issue)
https://github.com/kovidgoyal/calibre/security/advisories/GHSA-4926-v9px-wv7v

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
[trixie] - calibre <no-dsa> (Minor issue)[bookworm] - calibre <no-dsa> (Minor issue)https://github.com/kovidgoyal/calibre/security/advisories/GHSA-4926-v9px-wv7v

OS impact

OSVersionStatusFixed in
debian debianbookwormaffected
debian debianbullseyeaffected
debian debianforkyfixed9.6.0+ds+~0.10.5-1
debian debiansidfixed9.6.0+ds+~0.10.5-1
debian debiantrixieaffected

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.