PT-2026-22384 · Calibre · Calibre

Mistz1

·

Published

2026-01-01

·

Updated

2026-04-21

·

CVE-2026-27810

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions calibre versions prior to 9.4.0
Description calibre is an e-book manager for viewing, converting, editing, and cataloging e-books. A HTTP Response Header Injection exists in the calibre Content Server for versions before 9.4.0. An authenticated user can inject arbitrary HTTP headers into server responses through an unsanitized content disposition query parameter. This occurs in the /get/ and /data-files/get/ API endpoints. The issue is exploitable by any authenticated user, potentially through a crafted link. All users running the calibre Content Server with authentication enabled are affected.
Recommendations Update to calibre version 9.4.0 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-27810
GHSA-5FPJ-FXW7-8GRW
OPENSUSE-SU-2026:10587-1

Affected Products

Calibre