---
id: CVE-2026-6657
title: >-
  A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an
  attacker to bypass CORS origin validation when the `allow_origin_pat`
  configuration is used
summary: >-
  A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an
  attacker to bypass CORS origin validation when the `allow_origin_pat`
  configuration is used. The issue arises from the use of `re.match()` for
  validating the `Ori…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-346
vendor: jupyter
product: jupyter_server
affected:
  - 'jupyter_server >= 1.12.0, <= 2.17.0'
published: '2026-06-03'
updated: '2026-06-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-6657'
references:
  - url: 'https://huntr.com/bounties/18f642db-3569-43b3-b58d-ff97be4b09d7'
    label: security@huntr.dev
  - url: 'https://huntr.com/bounties/18f642db-3569-43b3-b58d-ff97be4b09d7'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00271
epssPercentile: 0.1714
ingestedAt: '2026-07-01T09:50:45.928Z'
---

## Overview

A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation when the `allow_origin_pat` configuration is used. The issue arises from the use of `re.match()` for validating the `Origin` header, which only anchors at the start of the string. This allows attacker-controlled domains such as `trusted.example.com.evil.com` to pass validation against patterns intended to match `trusted.example.com`. The vulnerability affects multiple locations in the codebase, including CORS headers, WebSocket connections, referer validation, and login redirects, potentially enabling phishing attacks, arbitrary code execution, and unauthorized access to sensitive API responses.

## Affected

- `jupyter_server >= 1.12.0, <= 2.17.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
