Known vulnerabilities in Jupyter Server

Vendor: Jupyter
Software CPE: cpe:2.3:a:jupyter:jupyter_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 14
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Jupyter Server Jupyter Server is affected by 14 known vulnerabilities: 1 high, 5 medium, 8 low Critical High Medium Low

Vulnerabilities (14)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU146867 - Information Exposure Through Log Files
CWE-532 Low
No
No
2.21.0 03.09.2026 SB2026090355
#VU146866 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-44727
CWE-79 Low
No
No
2.20.0 03.09.2026 SB2026090354
SB2026090362
#VU146865 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-35397
CWE-22 Low
No
No
2.18.0 03.09.2026 SB20260505104
#VU130163 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2025-61669
CWE-601 Medium
No
No
2.18.0 05.05.2026 SB20260505104
#VU130162 - Insufficient Session Expiration
CVE-2026-40934
CWE-613 Low
No
No
2.18.0 05.05.2026 SB20260505104
#VU130161 - Regular Expression without Anchors
CVE-2026-40110
CWE-777 Medium
No
No
2.18.0 05.05.2026 SB20260505104
#VU99615 - Exposure of sensitive information to an unauthorized actor
CVE-2024-35178
CWE-200 High
No
No
2.14.1 01.11.2024 SB2024110168
SB2024110184
#VU83857 - Information Exposure Through an Error Message
CVE-2023-49080
CWE-209 Medium
No
No
2.11.2 05.12.2023 SB2023120505
SB2023120536
SB2023120537
and 1 more
#VU80088 - Improper Access Control
CVE-2023-40170
CWE-284 Medium
No
No
2.7.2 29.08.2023 SB2023082923
SB2023083133
SB2023090128
and 1 more
#VU80087 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2023-39968
CWE-601 Low
No
No
2.7.2 29.08.2023 SB2023082923
SB2023083133
SB2023090128
and 1 more
#VU130158 - Exposure of sensitive information to an unauthorized actor
CVE-2022-29241
CWE-200 Low
No
No
1.17.1, 2.0.0 14.06.2022 SB2022061473
#VU61604 - Information Exposure Through Log Files
CVE-2022-24757
CWE-532 Medium
No
No
1.15.4 24.03.2022 SB2022032415
#VU130159 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2020-26275
CWE-601 Low
No
No
1.1.1 16.12.2020 SB2020121636
#VU130160 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2020-26232
CWE-601 Low
No
No
1.0.6 18.11.2020 SB2020111845