Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2628▼ 312 respecto a la semana anterior
Críticas / altas1351▲ 89 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.1) | 0.42% | — | Jupyter ServerAI | 17/9/2026 | 24/9/2026 | Jupyter Server is the backend for Jupyter web applications. Prior to version 2.21.0, the 5xx request logging path in jupyter_server/log.py copies the Referer header into a JSON header block without applying the token scrubbing used for the request URI. A request that returns HTTP 500 while the Referer contains a… | |
| Modificada | Crítica (9.3) | 0.44% | — | Jupyter Server | 22/6/2026 | 28/8/2026 | Jupyter Server is the backend for Jupyter web applications. Prior to 2.20, the nbconvert HTTP handlers in jupyter_server render user-authored notebook HTML under the Jupyter origin without a sandbox directive in their Content-Security-Policy. Combined with nbconvert.HTMLExporter's default non-sanitizing behavior, a… | |
| Analizada | Alta (8.8) | 0.27% | — | Jupyter Server | 3/6/2026 | 21/7/2026 | A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation when the `allow_origin_pat` configuration is used. The issue arises from the use of `re.match()` for validating the `Origin` header, which only anchors at the start of the string. This allows… | |
| Analizada | Alta (8.1) | 0.55% | — | Jupyter Server | 2/6/2026 | 22/7/2026 | A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an incorrect root directory boundary check in the _get_os_path() function within jupyter_server/services/contents/fileio.py. The check uses startswith(root) without appending a trailing path separator, allowing sibling directories with names… | |
| Analizada | Alta (7.6) | 0.38% | — | Jupyter Server | 5/5/2026 | 25/7/2026 | Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign authentication cookies is persisted to a static file at ~/.local/share/jupyter/runtime/jupyter_cookie_secret and is never rotated when a user changes their password. After a password reset and server… | |
| Modificada | Alta (7.6) | 0.47% | — | Jupyter Server | 5/5/2026 | 24/7/2026 | Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation uses Python's re.match() to check incoming origins against the allow_origin_pat configuration value. Because re.match() only anchors at the start of the string and does not require a full match, a… | |
| Modificada | Alta (7.6) | 0.67% | — | Jupyter Server | 5/5/2026 | 28/8/2026 | Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated user to escape the configured root_dir and access sibling directories whose names begin with the same prefix as the root_dir. For example, with a root_dir… | |
| Analizada | Media (6.3) | 0.24% | — | Jupyter Server | 5/5/2026 | 30/9/2026 | Jupyter Server is the backend for Jupyter web applications. In jupyter_server versions through 2.17.0, the next query parameter in the login flow is insufficiently validated in `LoginFormHandler._redirect_safe()`, which allows redirects to arbitrary external domains via values such as `///example.com`. An attacker can… | |
| Analizada | Media (6.1) | 0.45% | — | Jupyter Server Proxy | 11/6/2024 | 17/6/2026 | Jupyter Server Proxy allows users to run arbitrary external processes alongside their notebook server and provide authenticated web access to them. Versions of 3.x prior to 3.2.4 and 4.x prior to 4.2.0 have a reflected cross-site scripting (XSS) issue. The `/proxy` endpoint accepts a `host` path segment in the format… | |
| Modificada | Alta (7.5) | 0.70% | — | Jupyter Server | 6/6/2024 | 17/6/2026 | The Jupyter Server provides the backend for Jupyter web applications. Jupyter Server on Windows has a vulnerability that lets unauthenticated attackers leak the NTLMv2 password hash of the Windows user running the Jupyter server. An attacker can crack this password to gain access to the Windows machine hosting the… | |
| Analizada | Crítica (9.8) | 1.0% | — | Jupyter Server Proxy | 20/3/2024 | 17/6/2026 | Jupyter Server Proxy allows users to run arbitrary external processes alongside their Jupyter notebook servers and provides authenticated web access. Prior to versions 3.2.3 and 4.1.1, Jupyter Server Proxy did not check user authentication appropriately when proxying websockets, allowing unauthenticated access to… | |
| Modificada | Media (4.3) | 0.84% | — | Jupyter Server | 4/12/2023 | 17/6/2026 | The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupyter notebook, JupyterLab, and Voila. Unhandled errors in API requests coming from an authenticated user include traceback information, which can include path information. There is no known… | |
| Modificada | Media (6.1) | 0.62% | — | Jupyter Server | 28/8/2023 | 17/6/2026 | jupyter-server is the backend for Jupyter web applications. Improper cross-site credential checks on `/files/` URLs could allow exposure of certain file contents, or accessing files when opening untrusted files via "Open image in new tab". This issue has been addressed in commit `87a49272728` which has been included… | |
| Modificada | Media (6.1) | 0.68% | — | Jupyter Server | 28/8/2023 | 17/6/2026 | jupyter-server is the backend for Jupyter web applications. Open Redirect Vulnerability. Maliciously crafted login links to known Jupyter Servers can cause successful login or an already logged-in session to be redirected to arbitrary sites, which should be restricted to Jupyter Server-served URLs. This issue has been… | |
| Modificada | Alta (8.8) | 0.95% | — | Jupyter Server | 14/6/2022 | 17/6/2026 | Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupyter Notebook. Prior to version 1.17.1, if notebook server is started with a value of `root_dir` that contains the starting user's home directory, then the underlying REST API can be used to leak… | |
| Modificada | Alta (7.5) | 1.3% | — | Jupyter Server | 23/3/2022 | 17/6/2026 | The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications. Prior to version 1.15.4, unauthorized actors can access sensitive information from server logs. Anytime a 5xx error is triggered, the auth cookie and other header values are recorded in Jupyter… | |
| Modificada | Alta (7.1) | 1.1% | — | Jupyter Server Proxy | 25/1/2022 | 17/6/2026 | Jupyter Server Proxy is a Jupyter notebook server extension to proxy web services. Versions of Jupyter Server Proxy prior to 3.2.1 are vulnerable to Server-Side Request Forgery (SSRF). Any user deploying Jupyter Server or Notebook with jupyter-proxy-server extension enabled is affected. A lack of input validation… | |
| Modificada | Media (6.1) | 1.4% | — | Jupyter Server | 21/12/2020 | 17/6/2026 | The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupyter notebook, JupyterLab, and Voila. In Jupyter Server before version 1.1.1, an open redirect vulnerability could cause the jupyter server to redirect the browser to a different malicious… | |
| Modificada | Media (5.4) | 1.0% | — | Jupyter Server | 24/11/2020 | 17/6/2026 | Jupyter Server before version 1.0.6 has an Open redirect vulnerability. A maliciously crafted link to a jupyter server could redirect the browser to a different website. All jupyter servers are technically affected, however, these maliciously crafted links can only be reasonably made for known jupyter server hosts. A… |