PT-2022-13423 · Unknown · Calibre-Web

CVE-2022-0767

·

Published

2022-03-07

·

Updated

2026-06-29

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions calibre-web versions prior to 0.6.17
Description The issue is related to Server-Side Request Forgery (SSRF) due to incomplete protection that can be bypassed via an HTTP redirect. An HTTP server set up to respond with a 302 redirect may redirect a request to localhost.
Recommendations For versions prior to 0.6.17, update to version 0.6.17 or later to resolve the issue. As a temporary workaround, consider restricting access to the HTTP redirect functionality to minimize the risk of exploitation.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-0767
GHSA-H65G-JFQG-2W6M
PYSEC-2026-306

Affected Products

Calibre-Web