CVE-2026-33205: calibre has Server-Side Request Forgery in ebook viewer backend
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a Server-Side Request Forgery vulnerability in the background-image endpoint of calibre e-book reader's web view allows an attacker to perform blind GET requests to arbitrary URLs and exfiltrate information out from the ebook sandbox. Version 9.6.0 patches the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33205?
CVE-2026-33205 is classified as a security vulnerability that poses a risk of Server-Side Request Forgery.
How do I fix CVE-2026-33205?
To address CVE-2026-33205, update to calibre version 9.6.0 or later.
What does CVE-2026-33205 affect?
CVE-2026-33205 affects versions of calibre prior to 9.6.0, specifically impacting the ebook viewer backend.
What type of vulnerability is CVE-2026-33205?
CVE-2026-33205 is a Server-Side Request Forgery vulnerability found in the background-image endpoint.
Who is affected by CVE-2026-33205?
Anyone using calibre versions prior to 9.6.0 is affected by CVE-2026-33205.