SB20260505104 - Multiple vulnerabilities in Jupyter Server
Published: May 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 vulnerabilities.
1) Regular Expression without Anchors (CVE-ID: CVE-2026-40110)
The vulnerability allows a remote attacker to disclose sensitive information and modify data.
The vulnerability exists due to regular expression without anchors in the allow_origin_pat Origin header validation when validating cross-origin requests. A remote attacker can use a controlled domain that prefixes a trusted origin to bypass validation and disclose sensitive information and modify data.
User interaction is required.
2) Insufficient Session Expiration (CVE-ID: CVE-2026-40934)
The vulnerability allows a remote user to maintain indefinite authenticated access.
The vulnerability exists due to insufficient session expiration in the authentication cookie handling when reusing previously issued authentication cookies after a password reset and server restart. A remote user can reuse a stolen or compromised authentication cookie to maintain indefinite authenticated access.
The issue affects deployments using password authentication.
3) Open redirect (CVE-ID: CVE-2025-61669)
The vulnerability allows a remote attacker to redirect users to arbitrary external domains.
The vulnerability exists due to url redirection to an untrusted site in LoginFormHandler._redirect_safe() when processing the next query parameter. A remote attacker can supply a crafted next parameter to redirect users to arbitrary external domains.
User interaction is required for a victim to follow the crafted login URL.
Remediation
Install update from vendor's website.
References
- https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-24qx-w28j-9m6p
- https://github.com/jupyter-server/jupyter_server/commit/057869a327c46730afede3eab0ca2d2e3e74acea
- https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-5mrq-x3x5-8v8f
- https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-qh7q-6qm3-653w
- https://github.com/jupyter-server/jupyter_server/commit/987ebdd5e188cdc49751b01a0d6782d686492a53