CVE-2026-21883General(bokeh / bokeh)

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Bokeh is an interactive visualization library written in Python. In versions 3.8.1 and below, if a server is configured with an allowlist (e.g., dashboard.corp), an attacker can register a domain like dashboard.corp.attacker.com (or use a subdomain if applicable) and lure a victim to visit it. The malicious site can then initiate a WebSocket connection to the vulnerable Bokeh server. Since the Origin header (e.g., http://dashboard.corp.attacker.com/) matches the allowlist according to the flawed logic, the connection is accepted. Once connected, the attacker can interact with the Bokeh server on behalf of the victim, potentially accessing sensitive data, or modifying visualizations. This issue is fixed in version 3.8.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1385

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bokeh

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
bokeh

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-09: 103-09
Signal classification1 categories
General
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • DailyCVE@dailycve
    General

    🟠 Bokeh, Origin Validation Bypass, #CVE-2026-21883 (Medium) https://dailycve.com/bokeh-origin-validation-bypass-cve-2026-21883-medium/

    Post summary

    A short notice announcing CVE-2026-21883, a Medium‑severity origin‑validation bypass in Bokeh, with only a link for further information.

    0000044
    166 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbokehbokeh-python-

Explore more