CVE-2026-27824: calibre has IP Ban Bypass via X-Forwarded-For Header Spoofing
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.4.0, the calibre Content Server's brute-force protection mechanism uses a ban key derived from both remoteaddr and the X-Forwarded-For header. Since the X-Forwarded-For header is read directly from the HTTP request without any validation or trusted-proxy configuration, an attacker can bypass IP-based bans by simply changing or adding this header, rendering the brute-force protection completely ineffective. This is particularly dangerous for calibre servers exposed to the internet, where brute-force protection is the primary defense against credential stuffing and password guessing attacks. Version 9.4.0 contains a fix for the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27824?
CVE-2026-27824 is classified as a moderate severity vulnerability affecting calibre prior to version 9.4.0.
How do I fix CVE-2026-27824?
To mitigate CVE-2026-27824, upgrade to calibre version 9.4.0 or later.
What does CVE-2026-27824 affect?
CVE-2026-27824 affects the calibre Content Server's brute-force protection mechanism.
What technique is used in CVE-2026-27824 for bypassing restrictions?
CVE-2026-27824 allows IP ban bypass via X-Forwarded-For header spoofing.
Is CVE-2026-27824 present in all versions of calibre?
CVE-2026-27824 is present in all versions of calibre prior to 9.4.0.