Home

Description

ReDoS in strip_whitespaces() function in cps/string_helper.py in Calibre Web and Autocaliweb allows unauthenticated remote attackers to cause denial of service via specially crafted username parameter that triggers catastrophic backtracking during login. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1.

PUBLISHED Reserved 2025-07-01 | Published 2025-07-24 | Updated 2025-07-25 | Assigner Fluid Attacks




HIGH: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-1333 Inefficient Regular Expression Complexity

Product status

Default status
unaffected

0.6.24 (custom)
affected

Default status
unaffected

0.7.0 (custom) before 0.7.1
affected

References

fluidattacks.com/advisories/megadeth third-party-advisory

github.com/janeczku/calibre-web product

github.com/gelbphoenix/autocaliweb product

cve.org (CVE-2025-6998)

nvd.nist.gov (CVE-2025-6998)

Download JSON