
🚨 High - Jupyter Server access bypass (CVE-2026-40110, CVE-2026-35397) jupyter-server has two validation flaws: CORS Origin bypass via re.match() and path traversal via incorrect startswith() root checks. 👉 Affects <= 2.17.0 👉 Update to 2.18.0 immediately
Post summary
High severity CVEs for Jupyter Server with disallowed access bypass and path traversal, patched by upgrading to 2.18.0.


