Regular Expression without Anchors in Jupyter Server - CVE-2026-40110
Published: May 5, 2026
Jupyter Server
Jupyter
Description
The vulnerability allows a remote attacker to disclose sensitive information and modify data.
The vulnerability exists due to regular expression without anchors in the allow_origin_pat Origin header validation when validating cross-origin requests. A remote attacker can use a controlled domain that prefixes a trusted origin to bypass validation and disclose sensitive information and modify data.
User interaction is required.