CVE-2026-33205
Last modified
CVE-2026-33205 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a Server-Side Request Forgery vulnerability in the background-image endpoint of calibre e-book reader's web view allows an attacker to perform blind GET requests to arbitrary URLs and exfiltrate information out from the ebook sandbox. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a Server-Side Request Forgery vulnerability in the background-image endpoint of calibre e-book reader's web view allows an attacker to perform blind GET requests to arbitrary URLs and exfiltrate information out from the ebook sandbox. Version 9.6.0 patches the issue.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Calibre-Ebook | Calibre | < 9.6.0 |
References
- https://github.com/kovidgoyal/calibre/security/advisories/GHSA-4926-v9px-wv7vExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-33205?
How severe is CVE-2026-33205?
How do I fix CVE-2026-33205?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-33197AMI APTIOV contains a vulnerability in BIOS where a privileg…8.7
- CVE-2026-3320Reflected Cross-Site Scripting (XSS) in the latest demo vers…5.1
- CVE-2026-33201Digital Photo Frame GH-WDF10A provided by GREEN HOUSE CO., L…7
- CVE-2026-33202Active Storage allows users to attach cloud and local files …9.1
- CVE-2026-33203SiYuan is a personal knowledge management system. Prior to v…7.5
- CVE-2026-33204SimpleJWT is a simple JSON web token library written in PHP.…7.5
- CVE-2026-33206calibre is a cross-platform e-book manager for viewing, conv…6.3
- CVE-2026-33207DataEase is an open-source data visualization and analytics …8.8
- CVE-2026-33208Roxy-WI is a web interface for managing Haproxy, Nginx, Apac…8.8
- CVE-2026-33209Avo is a framework to create admin panels for Ruby on Rails …6.1
- CVE-2026-3321A vulnerability of authorization bypass through user-control…8.7
- CVE-2026-33210Ruby JSON is a JSON implementation for Ruby. From version 2.…9.1
Are you affected by CVE-2026-33205?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
