VulnSea

jupyter-server has 13 CVEs on record between 2020 and 2026. Disclosures have slowed: 1 in the last 90 days after 5 in the 90 before. The busiest recent month was May 2026 with 3. The median CVSS is 6.1 (medium). None have a confirmed exploitation report. Most affected products: jupyter-server (12), jupyter_server (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.1
Publish → KEV
Last 90 days
1 prev 5

Products

  • jupyter-server 12
  • jupyter_server 1
13
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

jupyter-server vulnerabilities

CVEs affecting jupyter-server, newest first. Open any entry for full detail, references, and exploit status.

13 CVEsRSS

CVE-2026-86049High· 7.1
5d ago

Jupyter Server is the backend for Jupyter web applications

Jupyter Server is the backend for Jupyter web applications. Prior to version 2.21.0, the 5xx request logging path in jupyter_server/log.py copies the Referer header into a JSON header block without applying the token scrubbing used for t…

Twilightjupyter-server · jupyter_serverEPSS 0.24%via NVD
CVE-2026-44727Medium· 5.4
3mo ago

Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP

Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP

Sunlitjupyter-server · jupyter-serverEPSS 0.44%via OSV
CVE-2026-5422Medium· 6.8
3mo ago

Jupyter Server vulnerable to Path Traversal via incorrect root directory boundary check in _get_os_path()

Jupyter Server vulnerable to Path Traversal via incorrect root directory boundary check in _get_os_path()

Sunlitjupyter-server · jupyter-serverEPSS 0.44%via OSV
CVE-2025-61669Medium
4mo ago

Jupyter Server has an open redirection vulnerability in `next` query parameter

Jupyter Server has an open redirection vulnerability in `next` query parameter

Sunlitjupyter-server · jupyter-serverEPSS 0.27%via OSV
CVE-2026-40934Medium· 6.8
4mo ago

Jupyter Server's Authentication Cookies Remain Valid After Password Reset and Server Restart

Jupyter Server's Authentication Cookies Remain Valid After Password Reset and Server Restart

Sunlitjupyter-server · jupyter-serverEPSS 0.31%via OSV
CVE-2026-40110High
4mo ago

Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat`

Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat`

Twilightjupyter-server · jupyter-serverEPSS 0.34%via OSV
CVE-2024-35178High· 7.5
2y ago

Jupyter server on Windows discloses Windows user password hash

Jupyter server on Windows discloses Windows user password hash

Twilightjupyter-server · jupyter-serverEPSS 0.70%via OSV
CVE-2023-49080Medium· 4.3
2y ago

jupyter-server errors include tracebacks with path information

jupyter-server errors include tracebacks with path information

Sunlitjupyter-server · jupyter-serverEPSS 0.84%via OSV
CVE-2023-39968Medium· 6.1
3y ago

Open Redirect Vulnerability in jupyter-server

Open Redirect Vulnerability in jupyter-server

Sunlitjupyter-server · jupyter-serverEPSS 0.68%via OSV
CVE-2023-40170Medium· 4.6
3y ago

cross-site inclusion (XSSI) of files in jupyter-server

cross-site inclusion (XSSI) of files in jupyter-server

Sunlitjupyter-server · jupyter-serverEPSS 0.62%via OSV
CVE-2022-29241High· 7.1
4y ago

Jupyter server Token bruteforcing

Jupyter server Token bruteforcing

Twilightjupyter-server · jupyter-serverEPSS 0.93%via OSV
CVE-2020-26275Medium· 6.1
5y ago

Jupyter Server open redirect vulnerability

Jupyter Server open redirect vulnerability

Sunlitjupyter-server · jupyter-serverEPSS 1.4%via OSV
CVE-2020-26232Medium· 4.1
5y ago

Open redirect in Jupyter Server

Open redirect in Jupyter Server

Sunlitjupyter-server · jupyter-serverEPSS 1.0%via OSV
jupyter-server vulnerabilities (CVEs) · VulnSea