Critical severity9.8NVD Advisory· Published Jan 30, 2022· Updated Jun 17, 2026
CVE-2022-0339
CVE-2022-0339
Description
Server-Side Request Forgery (SSRF) in Pypi calibreweb prior to 0.6.16.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
calibrewebPyPI | < 0.6.16 | 0.6.16 |
Affected products
3cpe:2.3:a:janeczku:calibre-web:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:janeczku:calibre-web:*:*:*:*:*:*:*:*range: <0.6.16
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
7- github.com/janeczku/calibre-web/commit/3b216bfa07ec7992eff03e55d61732af6df9bb92nvdPatchThird Party AdvisoryWEB
- huntr.dev/bounties/499688c4-6ac4-4047-a868-7922c3eab369nvdExploitIssue TrackingPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-4w8p-x6g8-fv64ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-0339ghsaADVISORY
- github.com/janeczku/calibre-web/commit/35f6f4c727c887f8f3607fe3233dbc1980d15020ghsaWEB
- github.com/janeczku/calibre-web/releases/tag/0.6.16ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/calibreweb/PYSEC-2022-23.yamlghsaWEB
News mentions
0No linked articles in our index yet.