Regular Expression without Anchors in Jupyter Server - CVE-2026-40110
Published: May 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information and modify data.
The vulnerability exists due to regular expression without anchors in the allow_origin_pat Origin header validation when validating cross-origin requests. A remote attacker can use a controlled domain that prefixes a trusted origin to bypass validation and disclose sensitive information and modify data.
User interaction is required.
Affected software
openEuler
python-jupyter-server
python3-jupyter-server
How to mitigate CVE-2026-40110
python-jupyter-server - addressed in versions 2.13.0-3, 2.13.0-4
python3-jupyter-server - addressed in versions 2.13.0-3, 2.13.0-4