VYPR

Jupyter Server

by Pypi

CVEs (1)

  • CVE-2026-6657MedJun 3, 2026
    risk 0.40cvss 6.1epss

    A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation when the `allow_origin_pat` configuration is used. The issue arises from the use of `re.match()` for validating the `Origin` header, which only anchors at the…

VYPR — Vulnerability Intelligence