← Back to all sparks
K

Kavita

COLLAB
Velocity0.0

Self-hosted digital library for books comics and manga

A self-hosted reading server that spent two releases becoming infrastructure, then paid for it with a CVE.

self-hostedebook-readeroidcsecurity-hardeningthird-party-apikavita-plus
Current state
Kavita ships two to four substantial releases a year with hotfixes trailing each one, and the last two years moved it well past a comic reader: OIDC login, an annotation system, a rebuilt epub reader, a reading-list overhaul, a stats system, and a scanner reported 50x faster. The most recent release is a critical security hotfix carrying CVE-2026-47202 that affects every prior version. Kavita+ remains the paid tier where metadata features land first.
Where it's heading
The arc is a hobby-scale project taking on the obligations of infrastructure — standard auth, an external API contract for third-party clients, sync with other readers, and formal vulnerability disclosure. Each of those decisions expands the attack surface, and the 0.9.x line shows the bill arriving: security hardening now leads the release notes rather than following them. The team has also visibly grown from one maintainer to a named pair, which is what made the parallel reader and foundation rewrites possible.
Prediction
The next release is likely the delayed scanner-improvement work that 0.8.7 displaced, with continued API hardening rather than new reader surfaces. Expect the CVE details to be published once adoption of 0.9.0.2 is high enough.

Recent moves

  1. 2mo ago

    v0.9.0.2 - Security Hotfix

    A critical security hotfix for CVE-2026-47202 affecting all prior versions, bundled with reading-list and bookmark fixes. It is the sharpest illustration of the cost of the last two years: an app with OIDC, a public API and third-party clients now has to run a disclosure process.

    View source ↗
  2. 3mo ago

    v0.9.0 - Reading List Overhaul and Spring Cleaning

    Nearly 200 changelog items rebuilding two major UI systems, plus API hardening after several security reports and a fix for how often Kavita wrote to the database — noticeable on non-SSD hosts. Consolidation of the foundations laid in 0.8.8 and 0.8.9 rather than new direction.

    View source ↗
  3. 6mo ago

    Auth Keys endpoint smoothed out for external app authors

    A small hotfix whose only forward-looking piece is tidying the authkey-expires endpoint so third-party app developers hit consistent behaviour. The rest is theme resets and broken admin statistics tables.

    View source ↗
  4. 6mo ago

    v0.8.9 - New Stats pages, Journal Style reading, 50x Faster Scanner, and so much more!

    ⚡ SPARK

    The release where Kavita starts treating outside developers as a constituency: authentication is reworked around multiple mechanisms with JWT management removed from the integration path, alongside a new stats system and a scanner rewrite. Everything that followed — the external API polish, the OIDC hardening, the CVE process — descends from this.

    View source ↗
  5. 7mo ago

    v0.8.7 - Comic Metadata Downloading, Reading Profiles, Browse by Genre and More

    Comic metadata downloading lands behind Kavita+, alongside reading profiles, expanded browse-by support, KOReader sync and a revamped Mihon extension. The paid tier is where metadata enrichment accrues while the sync and extension work broadens the client surface.

    View source ↗
  6. 8mo ago

    v0.8.8 - Epub Reader Overhaul, an Annotation System and OIDC!

    ⚡ SPARK

    Three months of work delivering OIDC, an annotation and highlighting system, custom epub fonts and a rebuilt epub reader. OIDC in particular is the change that makes Kavita installable inside an organisation rather than only on a personal box.

    View source ↗