{"api_version":"v1","generated_at":"2026-10-09T11:15:00+00:00","product":{"cve_count":14,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-kovidgoyal-calibre-f2e1156e8750","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/calibre","name":"calibre","next_cursor":null,"observations":[{"affected":"< 9.12.0","affected_versions_present":true,"cve_id":"CVE-2026-73249","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73249","fixed":"9.12.0.","last_modified":"2026-08-12T12:43:31.031Z","patch_url":"https://github.com/kovidgoyal/calibre/security/advisories/GHSA-5x64-w63v-x2g6","primary_source":"","published":"2026-08-11T21:58:43.415Z"},{"affected":"< 9.12.0","affected_versions_present":true,"cve_id":"CVE-2026-73248","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73248","fixed":"9.12.0.","last_modified":"2026-08-12T13:52:18.881Z","patch_url":"https://github.com/kovidgoyal/calibre/security/advisories/GHSA-4f7g-rjfp-hmvx","primary_source":"","published":"2026-08-11T21:56:08.569Z"},{"affected":"< 9.10.0","affected_versions_present":true,"cve_id":"CVE-2026-53511","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-53511","fixed":"9.10.0.","last_modified":"2026-08-18T07:16:16.171Z","patch_url":"https://github.com/kovidgoyal/calibre/security/advisories/GHSA-2j4m-2q7x-2c47","primary_source":"","published":"2026-07-07T20:46:49.199Z"},{"affected":"< 9.6.0","affected_versions_present":true,"cve_id":"CVE-2026-33206","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33206","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-27T14:48:44.155Z","patch_url":"","primary_source":"","published":"2026-03-27T13:53:22.833Z"},{"affected":"< 9.6.0","affected_versions_present":true,"cve_id":"CVE-2026-33205","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33205","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-27T19:58:43.747Z","patch_url":"","primary_source":"","published":"2026-03-27T13:52:06.860Z"},{"affected":"< 9.5.0","affected_versions_present":true,"cve_id":"CVE-2026-30853","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-30853","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-13T19:42:26.573Z","patch_url":"","primary_source":"","published":"2026-03-13T19:00:09.925Z"},{"affected":"< 9.4.0","affected_versions_present":true,"cve_id":"CVE-2026-27824","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-27824","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-02T12:54:32.182Z","patch_url":"","primary_source":"","published":"2026-02-27T19:46:07.612Z"},{"affected":"< 9.4.0","affected_versions_present":true,"cve_id":"CVE-2026-27810","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-27810","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-02T12:53:36.368Z","patch_url":"https://github.com/kovidgoyal/calibre/security/advisories/GHSA-5fpj-fxw7-8grw","primary_source":"","published":"2026-02-27T19:44:39.106Z"},{"affected":"< 9.3.0","affected_versions_present":true,"cve_id":"CVE-2026-26065","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-26065","fixed":"9.3.0.","last_modified":"2026-02-20T16:41:32.281Z","patch_url":"https://github.com/kovidgoyal/calibre/commit/b6da1c3878c06eb1356cb0ec1106cb66e0e9bfb8","primary_source":"","published":"2026-02-20T01:54:03.128Z"},{"affected":"< 9.3.0","affected_versions_present":true,"cve_id":"CVE-2026-26064","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-26064","fixed":"9.3.0.","last_modified":"2026-02-20T15:34:24.625Z","patch_url":"https://github.com/kovidgoyal/calibre/commit/e1b5f9b45a5e8fa96c136963ad9a1d35e6adac62","primary_source":"","published":"2026-02-20T01:44:34.137Z"},{"affected":"< 9.2.0","affected_versions_present":true,"cve_id":"CVE-2026-25731","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-25731","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-06T21:02:01.147Z","patch_url":"https://github.com/kovidgoyal/calibre/commit/f0649b27512e987b95fcab2e1e0a3bcdafc23379","primary_source":"","published":"2026-02-06T20:14:35.822Z"},{"affected":"< 9.2.0","affected_versions_present":true,"cve_id":"CVE-2026-25635","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-25635","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-11T14:54:23.143Z","patch_url":"https://github.com/kovidgoyal/calibre/commit/9739232fcb029ac15dfe52ccd4fdb4a07ebb6ce9","primary_source":"","published":"2026-02-06T20:10:29.839Z"},{"affected":"< 9.2.0","affected_versions_present":true,"cve_id":"CVE-2026-25636","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-25636","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-11T14:51:19.827Z","patch_url":"https://github.com/kovidgoyal/calibre/commit/9484ea82c6ab226c18e6ca5aa000fa16de598726","primary_source":"","published":"2026-02-06T20:07:40.529Z"},{"affected":"< 8.14.0","affected_versions_present":true,"cve_id":"CVE-2025-64486","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-64486","fixed":"8.14.0.","last_modified":"2025-11-13T21:34:23.230Z","patch_url":"https://github.com/kovidgoyal/calibre/security/advisories/GHSA-hpwq-c98h-xp8g","primary_source":"","published":"2025-11-07T23:25:55.996Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"kovidgoyal"}}
