CVE-2026-33205 Details
Description
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a Server-Side Request Forgery vulnerability in the background-image endpoint of calibre e-book reader's web view allows an attacker to perform blind GET requests to arbitrary URLs and exfiltrate information out from the ebook sandbox. Version 9.6.0 patches the issue.
A server-side request forgery (SSRF) vulnerability has been identified in Calibre e-book reader versions prior to 9.6.0. This vulnerability exists in the background-image endpoint of the application's web view, where it allows an attacker to send blind GET requests to arbitrary URLs. As a result, information can be exfiltrated from the e-book sandbox. The vulnerability arises because the background-image endpoint can display images from external URLs, enabling scripts in the sandboxed e-book context to access outside resources. This could be exploited to retrieve contents of files included in the e-book, leveraging a path traversal vulnerability, without the user's knowledge or consent.
Users should update to Calibre version 9.6.0 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/kovidgoyal/calibre/security/advisories/GHSA-4926-v9px-wv7v | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| calibre-ebook calibre | < 9.6.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 30, 2026 | Initial Analysis | [email protected] |
| Mar 27, 2026 | New CVE Received | [email protected] |