CVE-2026-40110

EUVD-2026-27510
Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation uses Python's re.match() to check incoming origins against the allow_origin_pat configuration value. Because re.match() only anchors at the start of the string and does not require a full match, a pattern intended to match only a trusted domain (e.g., trusted.example.com) will also match any origin that begins with that domain followed by additional characters (e.g., trusted.example.com.evil.com). An attacker who controls such a domain can bypass the CORS origin restriction and make cross-origin requests to the Jupyter Server API from an untrusted site. This issue has been fixed in version 2.18.0.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.3 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 26.66%
Affected Products (NVD)
VendorProductVersion
jupyterjupyter_server
𝑥
< 2.18.0
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat Migration Toolkit for Applications 8.2
1784109883 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
jupyter-server
bookworm
postponed
bullseye
postponed
forky
2.20.0-3
fixed
sid
2.20.0-3
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jupyter-server
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage