CVE-2021-44686

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
07/12/2021
Last modified:
04/11/2025

Description

calibre before 5.32.0 contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service) in html_preprocess_rules in ebooks/conversion/preprocess.py.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:calibre-ebook:calibre:*:*:*:*:*:*:*:* 5.32.0 (excluding)
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*