CVE-2026-6657
jupyter jupyter/jupyter, jupyter server
A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation when the `allow_origin_pat` configuration is used. The issue arises from the use of `re.match()` for validating the `Origin` header, which only anchors at the start of the string. This allows attacker-controlled domains such as `trusted.example.com.evil.com` to pass validation against patterns intended to match `trusted.example.com`. The vulnerability affects multiple locations in the codebase, including CORS headers, WebSocket connections, referer validation, and login redir...
- CVSS
- 8.8
- EPSS
- 0.20% 9.58% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.04