Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-22540 | Calibre Web and Autocaliweb have a ReDoS vulnerability |
Github GHSA |
GHSA-2g7m-ph9x-7q7m | Calibre Web and Autocaliweb have a ReDoS vulnerability |
Fri, 25 Jul 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Janeczku
Janeczku calibre-web |
|
| Vendors & Products |
Janeczku
Janeczku calibre-web |
Fri, 25 Jul 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ReDoS in strip_whitespaces() function in cps/string_helper.py in Calibre Web and Autocaliweb allows unauthenticated remote attackers to cause denial of service via specially crafted username parameter that triggers catastrophic backtracking during login.This issue affects Calibre Web: 0.6.24; Autocaliweb: from 0.7.0 before 0.7.1. | ReDoS in strip_whitespaces() function in cps/string_helper.py in Calibre Web and Autocaliweb allows unauthenticated remote attackers to cause denial of service via specially crafted username parameter that triggers catastrophic backtracking during login. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1. |
Fri, 25 Jul 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ReDoS in strip_whitespaces() function in cps/string_helper.py in janeczku Calibre Web 0.6.24 (Nicolette) allows unauthenticated remote attackers to cause denial of service via specially crafted username parameter that triggers catastrophic backtracking during login. ReDoS in strip_whitespaces() function in cps/string_helper.py in gelbphoenix Autocaliweb 0.7.0 on allows unauthenticated remote attackers to cause denial of service via specially crafted username parameter that triggers catastrophic backtracking during login. | ReDoS in strip_whitespaces() function in cps/string_helper.py in Calibre Web and Autocaliweb allows unauthenticated remote attackers to cause denial of service via specially crafted username parameter that triggers catastrophic backtracking during login.This issue affects Calibre Web: 0.6.24; Autocaliweb: from 0.7.0 before 0.7.1. |
Thu, 24 Jul 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 24 Jul 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ReDoS in strip_whitespaces() function in cps/string_helper.py in janeczku Calibre Web 0.6.24 (Nicolette) allows unauthenticated remote attackers to cause denial of service via specially crafted username parameter that triggers catastrophic backtracking during login. ReDoS in strip_whitespaces() function in cps/string_helper.py in gelbphoenix Autocaliweb 0.7.0 on allows unauthenticated remote attackers to cause denial of service via specially crafted username parameter that triggers catastrophic backtracking during login. | |
| Title | Calibre Web 0.6.24 & Autocaliweb 0.7.0 - ReDoS | |
| Weaknesses | CWE-1333 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2025-07-25T13:17:33.295Z
Reserved: 2025-07-01T23:26:57.856Z
Link: CVE-2025-6998
Updated: 2025-07-24T19:50:13.054Z
Status : Deferred
Published: 2025-07-24T20:15:27.013
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-6998
No data.
OpenCVE Enrichment
Updated: 2025-07-25T15:53:56Z
EUVD
Github GHSA