Denial of Service Vulnerability in Calibre Web and Autocaliweb Products
CVE-2025-6998
8.7HIGH
What is CVE-2025-6998?
A vulnerability exists in the strip_whitespaces() function found in cps/string_helper.py of both Calibre Web and Autocaliweb. This issue allows unauthenticated attackers to exploit the login functionality by sending specially crafted username parameters. These parameters cause catastrophic backtracking in the regular expression processing, potentially leading to a denial of service, thereby affecting the availability of the affected systems.
Affected Version(s)
Autocaliweb Linux 0.7.0 < 0.7.1
Calibre Web Linux 0.6.24