FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Calibre Web -- two vulnerabilities

Affected packages
0.6.24 <= py310-calibreweb < 0.6.27
0.6.24 <= py311-calibreweb < 0.6.27
0.6.24 <= py312-calibreweb < 0.6.27
0.6.24 <= py313-calibreweb < 0.6.27
0.6.24 <= py313t-calibreweb < 0.6.27
0.6.24 <= py314-calibreweb < 0.6.27
0.6.24 <= py314t-calibreweb < 0.6.27
0.6.24 <= py315-calibreweb < 0.6.27

Details

VuXML ID e87b74fa-940d-11f1-b046-3c7c3fba4204
Discovery 2025-07-24
Entry 2026-08-09

The Calibre Web Team reports:

ReDoS in strip_whitespaces() function in cps/string_helper.py in Calibre Web and Autocaliweb allows unauthenticated remote attackers to cause denial of service via specially crafted username parameter that triggers catastrophic backtracking during login.
This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1.

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS Command Injection.
This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1.

References

CVE Name CVE-2025-6998
CVE Name CVE-2025-7404
URL https://nvd.nist.gov/vuln/detail/CVE-2025-6998
URL https://nvd.nist.gov/vuln/detail/CVE-2025-7404