—
PYSEC-2026-1228
Calibre Web and Autocaliweb have a ReDoS vulnerability
Details
ReDoS in strip_whitespaces() function in cps/string_helper.py in Calibre Web and Autocaliweb allows unauthenticated remote attackers to cause denial of service via specially crafted username parameter that triggers catastrophic backtracking during login. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/calibreweb
Introduced in:
0No fixed version published yet for calibreweb (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-6998[ADVISORY]
- https://fluidattacks.com/advisories/megadeth[WEB]
- https://github.com/gelbphoenix/autocaliweb[WEB]
- https://github.com/janeczku/calibre-web[PACKAGE]
- https://pypi.org/project/calibreweb[PACKAGE]
- https://github.com/advisories/GHSA-2g7m-ph9x-7q7m[ADVISORY]