Debian dla-4705 : calibre - security update

high Nessus Plugin ID 330617

Synopsis

The remote Debian host is missing one or more security-related updates.

Description

The remote Debian 11 host has packages installed that are affected by multiple vulnerabilities as referenced in the dla-4705 advisory.

- ------------------------------------------------------------------------- Debian LTS Advisory DLA-4705-1 [email protected] https://www.debian.org/lts/security/ Abhijith PA July 29, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : calibre Version : 5.12.0+dfsg-1+deb11u5 CVE ID : CVE-2026-27810 CVE-2026-27824 CVE-2026-30853 CVE-2026-33205 CVE-2026-33206

Multiple vulnerabilities have been discovered in calibre, an e-book manager.

CVE-2026-27810

An HTTP Response Header Injection vulnerability in the calibre Content Server allows any authenticated user to inject arbitrary HTTP headers into server responses via an unsanitized `content_disposition` query parameter in the `/get/` and `/data-files/get/` endpoints

CVE-2026-27824

The calibre Content Server's brute-force protection mechanism uses a ban key derived from both `remote_addr` and the `X-Forwarded-For` header. Since the `X-Forwarded-For` header is read directly from the HTTP request without any validation or trusted-proxy configuration, an attacker can bypass IP-based bans by simply changing or adding this header, rendering the brute-force protection completely ineffective. This is particularly dangerous for calibre servers exposed to the internet, where brute-force protection is the primary defense against credential stuffing and password guessing attacks.

CVE-2026-30853

A path traversal vulnerability in the RocketBook (.rb) input plugin (src/calibre/ebooks/rb/reader.py) allows an attacker to write arbitrary files to any path writable by the calibre process when a user opens or converts a crafted .rb file.

CVE-2026-33205

A Server-Side Request Forgery vulnerability in the background-image endpoint of calibre e-book reader's web view allows an attacker to perform blind GET requests to arbitrary URLs and exfiltrate information out from the ebook sandbox.

CVE-2026-33206

A path traversal vulnerability exists in Calibre' handling of images in Markdown and other similar text-based files allowing an attacker to include arbitrary files from the file system into the converted book. Additionally, missing authentication and server-side request forgery in the background-image endpoint in the ebook reader web view allow the files to be exfiltrated without additional interaction.

For Debian 11 bullseye, these problems have been fixed in version 5.12.0+dfsg-1+deb11u5.

We recommend that you upgrade your calibre packages.

For the detailed security status of calibre please refer to its security tracker page at:
https://security-tracker.debian.org/tracker/calibre

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS

Tenable has extracted the preceding description block directly from the Debian security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade the calibre packages.

See Also

https://packages.debian.org/source/bullseye/calibre

https://security-tracker.debian.org/tracker/CVE-2026-27810

https://security-tracker.debian.org/tracker/CVE-2026-27824

https://security-tracker.debian.org/tracker/CVE-2026-30853

https://security-tracker.debian.org/tracker/CVE-2026-33205

https://security-tracker.debian.org/tracker/CVE-2026-33206

https://security-tracker.debian.org/tracker/source-package/calibre

Plugin Details

Severity: High

ID: 330617

File Name: debian_DLA-4705.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 7/29/2026

Updated: 7/29/2026

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.8

Percentile: 57.36

CVSS v2

Risk Factor: Medium

Base Score: 6.6

Temporal Score: 5.2

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:C/A:C

CVSS Score Source: CVE-2026-30853

CVSS v3

Risk Factor: High

Base Score: 8.2

Temporal Score: 7.4

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.2

Threat Score: 6.8

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N

CVSS Score Source: CVE-2026-33206

Vulnerability Information

CPE: cpe:/o:debian:debian_linux:11.0, p-cpe:/a:debian:debian_linux:calibre-bin, p-cpe:/a:debian:debian_linux:calibre

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/29/2026

Vulnerability Publication Date: 2/27/2026

Reference Information

CVE: CVE-2026-27810, CVE-2026-27824, CVE-2026-30853, CVE-2026-33205, CVE-2026-33206