CVE-2026-27824 | kovidgoyal calibre up to 9.3.x Proxy Configuration remote_addr/X-Forwarded-For excessive authentication (GHSA-vhxc-r7v8-2xrw / EUVD-2026-9057)
A vulnerability marked as problematic has been reported in kovidgoyal calibre up to 9.3.x. Affected by this vulnerability is an unknown functionality of the component Proxy Configuration Handler. This manipulation of the argument remote_addr/X-Forwarded-For causes improper restriction of excessive authentication attempts.
This vulnerability is registered as CVE-2026-27824. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.