VYPR

Jupyter Server

by Jqhph

CVEs (1)

  • CVE-2026-6657HigJun 3, 2026
    risk 0.57cvss 8.8epss 0.00

    A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation when the `allow_origin_pat` configuration is used. The issue arises from the use of `re.match()` for validating the `Origin` header, which only anchors at the…