CVE-2026-40110Disclosure(jupyter / jupyter_server)

LOWCVSS 7.3 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch jupyter jupyter_server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation uses Python's re.match() to check incoming origins against the allow_origin_pat configuration value. Because re.match() only anchors at the start of the string and does not require a full match, a pattern intended to match only a trusted domain (e.g., trusted.example.com) will also match any origin that begins with that domain followed by additional characters (e.g., trusted.example.com.evil.com). An attacker who controls such a domain can bypass the CORS origin restriction and make cross-origin requests to the Jupyter Server API from an untrusted site. This issue has been fixed in version 2.18.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-777CWE-625

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jupyter_server

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
jupyter_server

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-05: 3Patch / Workaround · 2026-05-05: 1Technical Details · 2026-05-05: 305-05
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
By indicator
Full discourse3 posts
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 High - Jupyter Server access bypass (CVE-2026-40110, CVE-2026-35397) jupyter-server has two validation flaws: CORS Origin bypass via re.match() and path traversal via incorrect startswith() root checks. 👉 Affects <= 2.17.0 👉 Update to 2.18.0 immediately

    Post summary

    High severity CVEs for Jupyter Server with disallowed access bypass and path traversal, patched by upgrading to 2.18.0.

    0002170
    121 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40110 Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation uses Python's re.match() to check incoming or… https://www.cve.org/CVERecord?id=CVE-2026-40110 ----- Traducción: CVE-2026-40110 Jup… http://infoflow.cloud`

    Post summary

    The text introduces CVE‑2026‑40110, indicating a flaw in Origin header validation in Jupyter Server and providing a link to the CVE record. It serves as a disclosure of the vulnerability details without reporting exploitation, patches, or PoC material.

    0000036
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40110 Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation uses Python's re.match() to check incoming or… https://www.cve.org/CVERecord?id=CVE-2026-40110

    Post summary

    The text announces CVE-2026-40110, describing a flaw in Jupyter Server’s Origin header validation that relies on Python’s re.match(), but provides no PoC, exploitation, patch, or active‑use information.

    00000238
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjupyterjupyter_server---

Explore more