{"id":"CVE-2026-40110","aliases":["GHSA-24qx-w28j-9m6p","PYSEC-2026-2187"],"url":"https://o3.security/vulnerability/CVE-2026-40110","summary":"jupyter-server CORS origin validation bypass via unanchored regex in allow_origin_pat","details":"Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation uses Python's re.match() to check incoming origins against the allow_origin_pat configuration value. Because re.match() only anchors at the start of the string and does not require a full match, a pattern intended to match only a trusted domain (e.g., trusted.example.com) will also match any origin that begins with that domain followed by additional characters (e.g., trusted.example.com.evil.com). An attacker who controls such a domain can bypass the CORS origin restriction and make cross-origin requests to the Jupyter Server API from an untrusted site. This issue has been fixed in version 2.18.0.","published":"2026-05-05T21:29:31.323Z","modified":"2026-09-12T03:46:09.095515049Z","cvss":null,"epss":{"score":0.0034,"percentile":0.27444,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"jupyter-server","fixedVersion":"2.18.0"}],"fix":{"url":"https://github.com/jupyter-server/jupyter_server/commit/057869a327c46730afede3eab0ca2d2e3e74acea","label":"jupyter-server/jupyter_server@057869a"},"references":[{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40110.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:43038"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-40110"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40110.json"},{"type":"ADVISORY","url":"https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-24qx-w28j-9m6p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40110"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2466912"},{"type":"FIX","url":"https://github.com/jupyter-server/jupyter_server/commit/057869a327c46730afede3eab0ca2d2e3e74acea"},{"type":"FIX","url":"https://github.com/jupyter-server/jupyter_server/commit/49b34392feaa97735b3b777e3baf8f22f2a14ed8"},{"type":"FIX","url":"https://github.com/jupyter-server/jupyter_server/pull/603"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-12T03:46:09.095515049Z"}}