Denial of Service Vulnerability in Calibre Web and Autocaliweb Products
CVE-2025-6998

8.7HIGH

Key Information:

Vendor
CVE Published:
24 July 2025

What is CVE-2025-6998?

A vulnerability exists in the strip_whitespaces() function found in cps/string_helper.py of both Calibre Web and Autocaliweb. This issue allows unauthenticated attackers to exploit the login functionality by sending specially crafted username parameters. These parameters cause catastrophic backtracking in the regular expression processing, potentially leading to a denial of service, thereby affecting the availability of the affected systems.

Affected Version(s)

Autocaliweb Linux 0.7.0 < 0.7.1

Calibre Web Linux 0.6.24

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-6998 : Denial of Service Vulnerability in Calibre Web and Autocaliweb Products