[Git][security-tracker-team/security-tracker][master] Add CVE-2026-30853/calibre

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Mar 14 09:30:10 GMT 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b2bbb3f1 by Salvatore Bonaccorso at 2026-03-14T10:29:05+01:00
Add CVE-2026-30853/calibre

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -458,7 +458,8 @@ CVE-2026-30915 (SFTPGo is an open source, event-driven file transfer solution. S
 CVE-2026-30914 (SFTPGo is an open source, event-driven file transfer solution. In SFTP ...)
 	- sftpgo <itp> (bug #1050829)
 CVE-2026-30853 (calibre is a cross-platform e-book manager for viewing, converting, ed ...)
-	TODO: check
+	- calibre 9.5.0+ds+~0.10.5-1
+	NOTE: https://github.com/kovidgoyal/calibre/security/advisories/GHSA-7mp7-rfrg-542x
 CVE-2026-2888 (The Formidable Forms plugin for WordPress is vulnerable to an authoriz ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-2879 (The GetGenie plugin for WordPress is vulnerable to Insecure Direct Obj ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b2bbb3f196e66f6a0ff3f4c4a4f940921f513ac6

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b2bbb3f196e66f6a0ff3f4c4a4f940921f513ac6
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260314/0b82169c/attachment.htm>


More information about the debian-security-tracker-commits mailing list