CRITICAL9.9
PYSEC-2026-306
Server-Side Request Forgery in calibreweb
Quick fix
PYSEC-2026-306 — calibreweb: upgrade to the fixed version with the command below.
pip install --upgrade 'calibreweb>=0.6.17'Details
calibreweb prior to version 0.6.17 is vulnerable to server-side request forgery (SSRF). This is a result of incomplete SSRF protection that can be bypassed via an HTTP redirect. An HTTP server set up to respond with a 302 redirect may redirect a request to `localhost`.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-0767[ADVISORY]
- https://github.com/janeczku/calibre-web/commit/965352c8d96c9eae7a6867ff76b0db137d04b0b8[WEB]
- https://github.com/janeczku/calibre-web[PACKAGE]
- https://huntr.dev/bounties/b26fc127-9b6a-4be7-a455-58aefbb62d9e[WEB]
- https://pypi.org/project/calibreweb[PACKAGE]
- https://github.com/advisories/GHSA-h65g-jfqg-2w6m[ADVISORY]