
CVE-2026-44775 Kavita is a cross platform reading server. Prior to 0.9.0, the ReaderController.GetImage endpoint is decorated with [AllowAnonymous], allowing completely unauthentica… https://www.cve.org/CVERecord?id=CVE-2026-44775
Post summary
The post announces CVE‑2026‑44775 in the Kavita reading server, noting that before version 0.9.0 the ReaderController.GetImage endpoint is marked [AllowAnonymous], allowing unauthenticated access.
