git: 050c7e40638d - main - security/vuxml: Document www/py-calibreweb vulnerabilities

From: Yusuf Yaman <nxjoseph_at_FreeBSD.org>
Date: Sun, 09 Aug 2026 16:32:17 UTC
The branch main has been updated by nxjoseph:

URL: https://cgit.FreeBSD.org/ports/commit/?id=050c7e40638d9163f6abc8fc1013a60b469e9a00

commit 050c7e40638d9163f6abc8fc1013a60b469e9a00
Author:     Yusuf Yaman <nxjoseph@FreeBSD.org>
AuthorDate: 2026-08-09 16:31:17 +0000
Commit:     Yusuf Yaman <nxjoseph@FreeBSD.org>
CommitDate: 2026-08-09 16:32:07 +0000

    security/vuxml: Document www/py-calibreweb vulnerabilities
    
    PR:             297375
    Approved by:    osa, vvd (Mentors, implicit)
---
 security/vuxml/vuln/2026.xml | 38 ++++++++++++++++++++++++++++++++++++++
 1 file changed, 38 insertions(+)

diff --git a/security/vuxml/vuln/2026.xml b/security/vuxml/vuln/2026.xml
index b1adab1ad8b2..99db853e32a5 100644
--- a/security/vuxml/vuln/2026.xml
+++ b/security/vuxml/vuln/2026.xml
@@ -1,3 +1,41 @@
+  <vuln vid="e87b74fa-940d-11f1-b046-3c7c3fba4204">
+    <topic>Calibre Web -- two vulnerabilities</topic>
+    <affects>
+      <package>
+	<name>py310-calibreweb</name>
+	<name>py311-calibreweb</name>
+	<name>py312-calibreweb</name>
+	<name>py313-calibreweb</name>
+	<name>py313t-calibreweb</name>
+	<name>py314-calibreweb</name>
+	<name>py314t-calibreweb</name>
+	<name>py315-calibreweb</name>
+	<range><ge>0.6.24</ge><lt>0.6.27</lt></range>
+      </package>
+    </affects>
+    <description>
+	<body xmlns="http://www.w3.org/1999/xhtml">
+	<p>The Calibre Web Team reports:</p>
+	<blockquote cite="https://github.com/advisories/GHSA-2g7m-ph9x-7q7m">
+	  <p>ReDoS in strip_whitespaces() function in cps/string_helper.py in Calibre Web and Autocaliweb allows unauthenticated remote attackers to cause denial of service via specially crafted username parameter that triggers catastrophic backtracking during login.<br/>This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1.</p>
+	</blockquote>
+	<blockquote cite="https://github.com/advisories/GHSA-qc4j-v7h6-xr5h">
+	  <p>Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS Command Injection.<br/>This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1.</p>
+	</blockquote>
+	</body>
+    </description>
+    <references>
+      <cvename>CVE-2025-6998</cvename>
+      <url>https://nvd.nist.gov/vuln/detail/CVE-2025-6998</url>
+      <cvename>CVE-2025-7404</cvename>
+      <url>https://nvd.nist.gov/vuln/detail/CVE-2025-7404</url>
+    </references>
+    <dates>
+      <discovery>2025-07-24</discovery>
+      <entry>2026-08-09</entry>
+    </dates>
+  </vuln>
+
   <vuln vid="54d19b85-93d4-11f1-8144-8447094a420f">
     <topic>Roundcube -- Multiple vulnerabilities</topic>
     <affects>