« Volver al listado

Jupyter

Jupyter Server: vulnerabilidades y CVE

Jupyter Server tiene 16 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE16
Últimos 12 meses8
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-86049Alta (7.1)0.42%—17 sept 2026
Jupyter Server is the backend for Jupyter web applications. Prior to version 2.21.0, the 5xx request logging path in jupyter_server/log.py copies the Referer header into a JSON header block without applying the token…
CVE-2026-44727Crítica (9.3)0.44%—22 jun 2026
Jupyter Server is the backend for Jupyter web applications. Prior to 2.20, the nbconvert HTTP handlers in jupyter_server render user-authored notebook HTML under the Jupyter origin without a sandbox directive in their…
CVE-2026-6657Alta (8.8)0.27%—3 jun 2026
A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation when the `allow_origin_pat` configuration is used. The issue arises from the use of `re.match()` for…
CVE-2026-5422Alta (8.1)0.55%—2 jun 2026
A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an incorrect root directory boundary check in the _get_os_path() function within jupyter_server/services/contents/fileio.py. The check uses…
CVE-2026-40934Alta (7.6)0.38%—5 may 2026
Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign authentication cookies is persisted to a static file at…
CVE-2026-40110Alta (7.6)0.47%—5 may 2026
Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation uses Python's re.match() to check incoming origins against the allow_origin_pat configuration…
CVE-2026-35397Alta (7.6)0.67%—5 may 2026
Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated user to escape the configured root_dir and access…
CVE-2025-61669Media (6.3)0.24%—5 may 2026
Jupyter Server is the backend for Jupyter web applications. In jupyter_server versions through 2.17.0, the next query parameter in the login flow is insufficiently validated in `LoginFormHandler._redirect_safe()`, which…
CVE-2024-35178Alta (7.5)0.70%—6 jun 2024
The Jupyter Server provides the backend for Jupyter web applications. Jupyter Server on Windows has a vulnerability that lets unauthenticated attackers leak the NTLMv2 password hash of the Windows user running the…
CVE-2023-49080Media (4.3)0.84%—4 dic 2023
The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupyter notebook, JupyterLab, and Voila. Unhandled errors in API requests coming from an…
CVE-2023-40170Media (6.1)0.62%—28 ago 2023
jupyter-server is the backend for Jupyter web applications. Improper cross-site credential checks on `/files/` URLs could allow exposure of certain file contents, or accessing files when opening untrusted files via…
CVE-2023-39968Media (6.1)0.68%—28 ago 2023
jupyter-server is the backend for Jupyter web applications. Open Redirect Vulnerability. Maliciously crafted login links to known Jupyter Servers can cause successful login or an already logged-in session to be…
CVE-2022-29241Alta (8.8)0.95%—14 jun 2022
Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupyter Notebook. Prior to version 1.17.1, if notebook server is started with a value of…
CVE-2022-24757Alta (7.5)1.3%—23 mar 2022
The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications. Prior to version 1.15.4, unauthorized actors can access sensitive information from server logs.…
CVE-2020-26275Media (6.1)1.4%—21 dic 2020
The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupyter notebook, JupyterLab, and Voila. In Jupyter Server before version 1.1.1, an open…
CVE-2020-26232Media (5.4)1.0%—24 nov 2020
Jupyter Server before version 1.0.6 has an Open redirect vulnerability. A maliciously crafted link to a jupyter server could redirect the browser to a different website. All jupyter servers are technically affected,…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1203 Exploitation for Client Execution3
  2. T1210 Exploitation of Remote Services3
  3. T1005 Data from Local System2
  4. T1059.007 JavaScript1
  5. T1078.001 Default Accounts1
  6. T1189 Drive-by Compromise1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Jupyter