Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-c3mw-737p-c7g2
  • PyPI/jupyter-server
Jupyter Server: 5xx request logging leaks token-bearing Referer header values 3 days ago
  • Fix available
  • Severity - 7.1 (High)
PYSEC-2026-3472
  • PyPI/jupyter-server
jupyter-server is vulnerable to CORS origin validation bypass when the `allow_origin_pat` configuration is used 23 Jul
  • No fix available
  • Severity - 6.1 (Medium)
PYSEC-2026-2532
  • PyPI/jupyter-server
Jupyter Server vulnerable to Path Traversal via incorrect root directory boundary check in _get_os_path() 13 Jul
  • Fix available
  • Severity - 6.8 (Medium)
PYSEC-2026-366
  • PyPI/jupyter-server
Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP 29 Jun
  • Fix available
  • Severity - 9.3 (Critical)
GHSA-fcw5-x6j4-ccmp
  • PyPI/jupyter-server
Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP 18 Jun
  • Fix available
  • Severity - 9.3 (Critical)
PYSEC-2026-69
  • PyPI/jupyter-server
See record for full details 05 May
  • Fix available
  • Severity - 6.8 (Medium)
PYSEC-2026-2187
  • PyPI/jupyter-server
See record for full details 05 May
  • Fix available
  • Severity - 7.3 (High)
PYSEC-2026-68
  • PyPI/jupyter-server
See record for full details 05 May
  • Fix available
  • Severity - 8.8 (High)
GHSA-5mrq-x3x5-8v8f
  • PyPI/jupyter-server
Jupyter Server's Authentication Cookies Remain Valid After Password Reset and Server Restart 05 May
  • Fix available
  • Severity - 7.6 (High)
GHSA-24qx-w28j-9m6p
  • PyPI/jupyter-server
Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat` 05 May
  • Fix available
  • Severity - 7.6 (High)
GHSA-5789-5fc7-67v3
  • PyPI/jupyter-server
Jupyter Server: Path Traversal via incorrect startswith() root directory check allows access to sibling directories 05 May
  • Fix available
  • Severity - 7.6 (High)
GHSA-qh7q-6qm3-653w
  • PyPI/jupyter-server
Jupyter Server has an open redirection vulnerability in `next` query parameter 05 May
  • Fix available
  • Severity - 6.0 (Medium)
PYSEC-2026-67
  • PyPI/jupyter-server
See record for full details 05 May
  • Fix available
  • Severity - 6.1 (Medium)
PYSEC-2024-236
  • PyPI/jupyter-server-proxy
  • github.com/jupyterhub/jupyter-server-proxy
See record for full details 11 Jun 2024
  • Fix available
  • Severity - 6.1 (Medium)
GHSA-fvcq-4x64-hqxr
  • PyPI/jupyter-server-proxy
Jupyter Server Proxy has a reflected XSS issue in host parameter 11 Jun 2024
  • Fix available
  • Severity - 9.6 (Critical)
GHSA-hrw6-wg82-cm62
  • PyPI/jupyter-server
Jupyter server on Windows discloses Windows user password hash 06 Jun 2024
  • Fix available
  • Severity - 7.5 (High)