CVE-2026-6657Jupyter · Jupyter_server
Vulnerability data via NVD (ingested)
A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation when the `allow_origin_pat` configuration is used. The issue arises from the use of `re.match()` for validating the `Origin` header, which only anchors at the start of the string. This allows attacker-controlled domains such as `trusted.example.com.evil.com` to pass validation against patterns intended to match `trusted.example.com`. The vulnerability affects multiple locations in the codebase, including CORS headers, WebSocket connections, referer validation, and login redirects, potentially enabling phishing attacks, arbitrary code execution, and unauthorized access to sensitive API responses.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-6657product:"Jupyter Jupyter Server"http.html:"Jupyter Server"More intel sources (5)
vuln:CVE-2026-6657vulnerabilities.cve_id: CVE-2026-6657CVE-2026-6657CVE-2026-6657"CVE-2026-6657" exploit -site:nvd.nist.gov