Executive brief
Jupyter Server, the backend for Jupyter web applications, is vulnerable to a security bypass that could allow unauthorized websites to interact with its API. Due to a flaw in how the server validates the origin of incoming requests, an attacker who controls a specifically named domain can trick the server into accepting malicious commands. This could lead to unauthorized access to user data or the ability to perform actions on behalf of a logged-in user.
Technical details
Jupyter Server (<= 2.17.0) uses Python's re.match() to validate the Origin header against the allow_origin_pat configuration. Because re.match() only anchors at the beginning of a string and does not enforce a full match, a pattern like 'trusted.example.com' will incorrectly validate malicious origins such as 'trusted.example.com.evil.com'. This allows an attacker to bypass Cross-Origin Resource Sharing (CORS) protections. By enticing an authenticated user to visit a malicious site, the attacker can execute cross-origin requests to the Jupyter Server API. The vulnerability is addressed in version 2.18.0 by switching to full-string matching.
Affected products
- Jupyter Jupyter Server <= 2.17.0
- Red Hat Migration Toolkit for Applications 8
- Red Hat Red Hat OpenShift AI (RHOAI)
Timeline
- 2026-05-05: disclosed
- 2026-05-05: advisory
- 2026-05-04: patched
References
- https://github.com/jupyter-server/jupyter_server/commit/057869a327c46730afede3eab0ca2d2e3e74acea
- https://github.com/jupyter-server/jupyter_server/commit/49b34392feaa97735b3b777e3baf8f22f2a14ed8
- https://github.com/jupyter-server/jupyter_server/pull/603
- https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-24qx-w28j-9m6p
- https://access.redhat.com/security/cve/CVE-2026-40110
- https://bugzilla.redhat.com/show_bug.cgi?id=2466912
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40110.json