HTTP Response Header Injection Vulnerability in Calibre by Kovid Goyal
CVE-2026-27810

6.4MEDIUM

Key Information:

Vendor

Kovidgoyal

Status
Vendor
CVE Published:
27 February 2026

What is CVE-2026-27810?

Calibre, a widely-used cross-platform e-book management software, contains a vulnerability in its Content Server that permits authenticated users to inject arbitrary HTTP headers into server responses. This exploitation arises from an unsanitized content_disposition query parameter within key endpoints. Attackers can leverage this flaw to manipulate server responses, potentially leading to further attacks or information disclosure. Users should upgrade to version 9.4.0 or later to mitigate this risk.

Affected Version(s)

calibre < 9.4.0

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.