CVE-2026-6657 — Jupyter Jupyter_server: A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS
A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation when the `allow_origin_pat` configuration is used. The issue arises from the use of `re.match()` for validating the `Origin` header, which only anchors at the start of the string. This allows attacker-controlled domains such as `trusted.example.com.evil.com` to pass validation against patterns intended to match `trusted.example.com`. The vulnerability affects m CVSSv3.1 8.8 (HIGH) · EPSS 10th percentile