jupyter-server has 13 CVEs on record between 2020 and 2026. Disclosures have slowed: 1 in the last 90 days after 5 in the 90 before. The busiest recent month was May 2026 with 3. The median CVSS is 6.1 (medium). None have a confirmed exploitation report. Most affected products: jupyter-server (12), jupyter_server (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.1
- Publish → KEV
- —
- Last 90 days
- 1 prev 5
Weakness classes
Products
- jupyter-server 12
- jupyter_server 1
Worst active — by depth score
CVE-2026-40110HighJupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat`41CVE-2024-35178High· 7.5Jupyter server on Windows discloses Windows user password hash41CVE-2026-86049High· 7.1Jupyter Server is the backend for Jupyter web applications39CVE-2022-29241High· 7.1Jupyter server Token bruteforcing39CVE-2026-5422Medium· 6.8Jupyter Server vulnerable to Path Traversal via incorrect root directory boundary check in _get_os_path() 37
jupyter-server vulnerabilities
CVEs affecting jupyter-server, newest first. Open any entry for full detail, references, and exploit status.
13 CVEsRSS
CVE-2026-86049High· 7.1Jupyter Server is the backend for Jupyter web applications
Jupyter Server is the backend for Jupyter web applications. Prior to version 2.21.0, the 5xx request logging path in jupyter_server/log.py copies the Referer header into a JSON header block without applying the token scrubbing used for t…
CVE-2026-44727Medium· 5.4Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP
Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP
CVE-2026-5422Medium· 6.8Jupyter Server vulnerable to Path Traversal via incorrect root directory boundary check in _get_os_path()
Jupyter Server vulnerable to Path Traversal via incorrect root directory boundary check in _get_os_path()
CVE-2025-61669MediumJupyter Server has an open redirection vulnerability in `next` query parameter
Jupyter Server has an open redirection vulnerability in `next` query parameter
CVE-2026-40934Medium· 6.8Jupyter Server's Authentication Cookies Remain Valid After Password Reset and Server Restart
Jupyter Server's Authentication Cookies Remain Valid After Password Reset and Server Restart
CVE-2026-40110HighJupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat`
Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat`
CVE-2024-35178High· 7.5Jupyter server on Windows discloses Windows user password hash
Jupyter server on Windows discloses Windows user password hash
CVE-2023-49080Medium· 4.3jupyter-server errors include tracebacks with path information
jupyter-server errors include tracebacks with path information
CVE-2023-39968Medium· 6.1Open Redirect Vulnerability in jupyter-server
Open Redirect Vulnerability in jupyter-server
CVE-2023-40170Medium· 4.6cross-site inclusion (XSSI) of files in jupyter-server
cross-site inclusion (XSSI) of files in jupyter-server
CVE-2022-29241High· 7.1Jupyter server Token bruteforcing
Jupyter server Token bruteforcing
CVE-2020-26275Medium· 6.1Jupyter Server open redirect vulnerability
Jupyter Server open redirect vulnerability
CVE-2020-26232Medium· 4.1Open redirect in Jupyter Server
Open redirect in Jupyter Server