Synopsis
The remote Debian host is missing one or more security-related updates.
Description
The remote Debian 11 host has packages installed that are affected by multiple vulnerabilities as referenced in the dla-4705 advisory.
- ------------------------------------------------------------------------- Debian LTS Advisory DLA-4705-1 [email protected] https://www.debian.org/lts/security/ Abhijith PA July 29, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------
Package : calibre Version : 5.12.0+dfsg-1+deb11u5 CVE ID : CVE-2026-27810 CVE-2026-27824 CVE-2026-30853 CVE-2026-33205 CVE-2026-33206
Multiple vulnerabilities have been discovered in calibre, an e-book manager.
CVE-2026-27810
An HTTP Response Header Injection vulnerability in the calibre Content Server allows any authenticated user to inject arbitrary HTTP headers into server responses via an unsanitized `content_disposition` query parameter in the `/get/` and `/data-files/get/` endpoints
CVE-2026-27824
The calibre Content Server's brute-force protection mechanism uses a ban key derived from both `remote_addr` and the `X-Forwarded-For` header. Since the `X-Forwarded-For` header is read directly from the HTTP request without any validation or trusted-proxy configuration, an attacker can bypass IP-based bans by simply changing or adding this header, rendering the brute-force protection completely ineffective. This is particularly dangerous for calibre servers exposed to the internet, where brute-force protection is the primary defense against credential stuffing and password guessing attacks.
CVE-2026-30853
A path traversal vulnerability in the RocketBook (.rb) input plugin (src/calibre/ebooks/rb/reader.py) allows an attacker to write arbitrary files to any path writable by the calibre process when a user opens or converts a crafted .rb file.
CVE-2026-33205
A Server-Side Request Forgery vulnerability in the background-image endpoint of calibre e-book reader's web view allows an attacker to perform blind GET requests to arbitrary URLs and exfiltrate information out from the ebook sandbox.
CVE-2026-33206
A path traversal vulnerability exists in Calibre' handling of images in Markdown and other similar text-based files allowing an attacker to include arbitrary files from the file system into the converted book. Additionally, missing authentication and server-side request forgery in the background-image endpoint in the ebook reader web view allow the files to be exfiltrated without additional interaction.
For Debian 11 bullseye, these problems have been fixed in version 5.12.0+dfsg-1+deb11u5.
We recommend that you upgrade your calibre packages.
For the detailed security status of calibre please refer to its security tracker page at:
https://security-tracker.debian.org/tracker/calibre
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Tenable has extracted the preceding description block directly from the Debian security advisory.
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
Solution
Upgrade the calibre packages.
Plugin Details
File Name: debian_DLA-4705.nasl
Agent: unix
Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus
Risk Information
Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:C/A:C
Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:H
Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C
Threat Vector: CVSS:4.0/E:P
Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Vulnerability Information
CPE: cpe:/o:debian:debian_linux:11.0, p-cpe:/a:debian:debian_linux:calibre-bin, p-cpe:/a:debian:debian_linux:calibre
Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l
Exploit Ease: Exploits are available
Patch Publication Date: 7/29/2026
Vulnerability Publication Date: 2/27/2026