{"id":"CVE-2022-2525","aliases":["GHSA-jg8w-wgx2-g7q4","PYSEC-2026-1231"],"title":"Improper Restriction of Excessive Authentication Attempts in calibreweb","summary":"Improper Restriction of Excessive Authentication Attempts in calibreweb","severity":"medium","vendor":"calibreweb","product":"calibreweb","ecosystem":"pip","affected":["calibreweb < 0.6.20"],"patched":["calibreweb 0.6.20"],"published":"2023-04-15","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-jg8w-wgx2-g7q4","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-2525"},{"url":"https://github.com/janeczku/calibre-web/commit/49e4f540c9b204c7e39b3c27ceadecd83ed60e7e"},{"url":"https://huntr.dev/bounties/9ff87820-c14c-4454-9764-406496254ef0"}],"tags":["osv","pip"],"epss":0.00769,"epssPercentile":0.5361,"ingestedAt":"2026-07-08T18:25:50.669Z","slug":"CVE-2022-2525","body":"## Overview\n\nImproper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web prior to 0.6.20.\n\n## Affected packages\n\n- `calibreweb < 0.6.20`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `calibreweb 0.6.20`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}