pypi

jupyter-server

View on pypi registry
32 Total advisories
32 Vulnerabilities
0 Malware

Dependency scanning

Check whether jupyter-server is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

HIGH 7.1
PyPI

CVE-2026-86049

Jupyter Server: 5xx request logging leaks token-bearing Referer header values

HIGH 7.1
PyPI

CVE-2026-35397

Jupyter Server: Path Traversal via incorrect startswith() root directory check allows access to sibling directories

MEDIUM 5.4
PyPI

CVE-2026-44727

Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP

UNKNOWN
PyPI

CVE-2025-61669

Jupyter Server has an open redirection vulnerability in `next` query parameter

MEDIUM 6.8
PyPI

CVE-2026-40934

Jupyter Server's Authentication Cookies Remain Valid After Password Reset and Server Restart

UNKNOWN
PyPI

CVE-2026-40110

Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat`

HIGH 7.5
PyPI

CVE-2024-35178

Jupyter server on Windows discloses Windows user password hash

MEDIUM 4.3
PyPI

CVE-2023-49080

jupyter-server errors include tracebacks with path information

MEDIUM 6.1
PyPI

CVE-2023-39968

Open Redirect Vulnerability in jupyter-server

MEDIUM 4.6
PyPI

CVE-2023-40170

cross-site inclusion (XSSI) of files in jupyter-server

HIGH 7.1
PyPI

CVE-2022-29241

Jupyter server Token bruteforcing

MEDIUM 4.1
PyPI

CVE-2020-26232

Open redirect in Jupyter Server

MEDIUM 6.8
PyPI

CVE-2026-5422

Duplicate Advisory: Jupyter Server vulnerable to Path Traversal via incorrect root directory boundary check in _get_os_path()

MEDIUM 6.1
PyPI

CVE-2026-6657

Duplicate Advisory: jupyter-server is vulnerable to CORS origin validation bypass when the `allow_origin_pat` configuration is used

MEDIUM 6.1
PyPI

CVE-2026-6657

jupyter-server is vulnerable to CORS origin validation bypass when the `allow_origin_pat` configuration is used

MEDIUM 6.8
PyPI

CVE-2026-5422

Jupyter Server vulnerable to Path Traversal via incorrect root directory boundary check in _get_os_path()

UNKNOWN
PyPI

CVE-2026-44727

Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP

HIGH 7.3
PyPI

CVE-2026-40110

CVE-2026-40110

UNKNOWN
PyPI

CVE-2020-26275

CVE-2020-26275

MEDIUM 6.1
PyPI

CVE-2020-26275

Jupyter Server open redirect vulnerability

MEDIUM 6.1
PyPI

CVE-2020-26275

CVE-2020-26275

HIGH 7.5
PyPI

CVE-2024-35178

CVE-2024-35178

MEDIUM 6.8
PyPI

CVE-2026-40934

CVE-2026-40934

HIGH 8.8
PyPI

CVE-2026-35397

CVE-2026-35397

MEDIUM 6.1
PyPI

CVE-2025-61669

CVE-2025-61669

MEDIUM 4.3
PyPI

CVE-2023-49080

CVE-2023-49080

MEDIUM 6.1
PyPI

CVE-2023-40170

CVE-2023-40170

MEDIUM 6.1
PyPI

CVE-2023-39968

CVE-2023-39968

UNKNOWN
PyPI

CVE-2022-29241

CVE-2022-29241

UNKNOWN
PyPI

CVE-2022-24757

CVE-2022-24757

HIGH 7.5
PyPI

CVE-2022-24757

Insertion of Sensitive Information into Log File in Jupyter notebook

UNKNOWN
PyPI

CVE-2020-26232

CVE-2020-26232

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes