CVE-2025-6998 is a regular expression denial-of-service vulnerability in the strip_whitespaces() function used by Calibre Web and Autocaliweb login processing. A crafted username causes catastrophic regular-expression backtracking, allowing an unauthenticated remote attacker to exhaust application resources and deny service. Calibre Web 0.6.24 (Nicolette) and Autocaliweb versions 0.7.0 through before 0.7.1 are affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Python proof-of-concept exploit for CVE-2025-6998, a Regular Expression Denial of Service (ReDoS) vulnerability in CalibreWeb version 0.6.24. The main file, exploit.py, is a command-line tool that takes a target URL and (optionally) a proxy and payload size. It first fetches a CSRF token from the target's main page, then crafts a POST request to the /login endpoint with a specially constructed username payload designed to trigger inefficient regex processing on the server. The payload consists of a null byte, a large number of tab characters (default 60,000), and another null byte, which is sent as the username. If the server is vulnerable, this can cause the login process to hang, resulting in a denial of service. The exploit is network-based, requires no authentication, and targets the /login endpoint of CalibreWeb 0.6.24. The repository is structured simply, with a single exploit script, a README, a license, and a .gitignore file.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.