HTTP Response Header Injection Vulnerability in Calibre by Kovid Goyal
CVE-2026-27810
6.4MEDIUM
What is CVE-2026-27810?
Calibre, a widely-used cross-platform e-book management software, contains a vulnerability in its Content Server that permits authenticated users to inject arbitrary HTTP headers into server responses. This exploitation arises from an unsanitized content_disposition query parameter within key endpoints. Attackers can leverage this flaw to manipulate server responses, potentially leading to further attacks or information disclosure. Users should upgrade to version 9.4.0 or later to mitigate this risk.
Affected Version(s)
calibre < 9.4.0
