Calibre Web and Autocaliweb have a ReDoS vulnerability
High severity
GitHub Reviewed
Published
Jul 24, 2025
to the GitHub Advisory Database
•
Updated Jul 28, 2025
Description
Published by the National Vulnerability Database
Jul 24, 2025
Published to the GitHub Advisory Database
Jul 24, 2025
Reviewed
Jul 28, 2025
Last updated
Jul 28, 2025
ReDoS in strip_whitespaces() function in cps/string_helper.py in Calibre Web and Autocaliweb allows unauthenticated remote attackers to cause denial of service via specially crafted username parameter that triggers catastrophic backtracking during login. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1.
References