Dependency scanning
Check whether jupyter-server is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-86049
Jupyter Server: 5xx request logging leaks token-bearing Referer header values
CVE-2026-35397
Jupyter Server: Path Traversal via incorrect startswith() root directory check allows access to sibling directories
CVE-2026-44727
Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP
CVE-2025-61669
Jupyter Server has an open redirection vulnerability in `next` query parameter
CVE-2026-40934
Jupyter Server's Authentication Cookies Remain Valid After Password Reset and Server Restart
CVE-2026-40110
Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat`
CVE-2024-35178
Jupyter server on Windows discloses Windows user password hash
CVE-2023-49080
jupyter-server errors include tracebacks with path information
CVE-2023-39968
Open Redirect Vulnerability in jupyter-server
CVE-2023-40170
cross-site inclusion (XSSI) of files in jupyter-server
CVE-2022-29241
Jupyter server Token bruteforcing
CVE-2020-26232
Open redirect in Jupyter Server
CVE-2026-5422
Duplicate Advisory: Jupyter Server vulnerable to Path Traversal via incorrect root directory boundary check in _get_os_path()
CVE-2026-6657
Duplicate Advisory: jupyter-server is vulnerable to CORS origin validation bypass when the `allow_origin_pat` configuration is used
CVE-2026-6657
jupyter-server is vulnerable to CORS origin validation bypass when the `allow_origin_pat` configuration is used
CVE-2026-5422
Jupyter Server vulnerable to Path Traversal via incorrect root directory boundary check in _get_os_path()
CVE-2026-44727
Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP
CVE-2026-40110
CVE-2026-40110
CVE-2020-26275
CVE-2020-26275
CVE-2020-26275
Jupyter Server open redirect vulnerability
CVE-2020-26275
CVE-2020-26275
CVE-2024-35178
CVE-2024-35178
CVE-2026-40934
CVE-2026-40934
CVE-2026-35397
CVE-2026-35397
CVE-2025-61669
CVE-2025-61669
CVE-2023-49080
CVE-2023-49080
CVE-2023-40170
CVE-2023-40170
CVE-2023-39968
CVE-2023-39968
CVE-2022-29241
CVE-2022-29241
CVE-2022-24757
CVE-2022-24757
CVE-2022-24757
Insertion of Sensitive Information into Log File in Jupyter notebook
CVE-2020-26232
CVE-2020-26232
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes