Server-Side Request Forgery (SSRF) in Calibre - CVE-2026-33205

 

Server-Side Request Forgery (SSRF) in Calibre - CVE-2026-33205

Published: June 29, 2026


Vulnerability identifier: #VU135814
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-33205
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform blind GET requests to arbitrary URLs and disclose sensitive information.

The vulnerability exists due to server-side request forgery in the background-image endpoint when processing a user-supplied URL from sandboxed e-book content. A remote attacker can supply a crafted URL to perform blind GET requests to arbitrary URLs and disclose sensitive information.

Exploitation can be used to reach services on the local network, and the issue can be chained with a separate path traversal issue to exfiltrate file contents from the e-book sandbox without user awareness.


Affected software

Calibre
Fedora
calibre

How to mitigate CVE-2026-33205

Install security update from vendor's website.

Calibre - update to 9.6.0
calibre - addressed in versions 9.6.0-1.fc43, 9.6.0-1.fc44

External References

Related Security Bulletins