Vulnerability index

Browse CVEs

55 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Gateway CRITICAL 10.0
CVE-2026-44181

Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In v…

Fix: 3.3.0+
Fix from $2,300 2026-07-16
Enterprise Gateway CRITICAL 10.0
CVE-2026-44182

Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In v…

Fix: 3.3.0+
Fix from $2,300 2026-07-16
Enterprise Gateway CRITICAL 9.8
CVE-2026-44180

Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. Vers…

Fix: 3.3.0+
Fix from $2,300 2026-07-16
Jupyterlab Git CRITICAL 9.0
CVE-2026-54527

JupyterLab Git is a Git extension for JupyterLab. From 0.30.0b3 before 0.54.0, the PlainTextDiff.ts createHeader() method passes Git filenames direct…

Fix: 0.54.0+
Fix from $2,300 2026-07-08
Jupyterlab Git HIGH 7.1
CVE-2026-54528

JupyterLab Git is a Git extension for JupyterLab. Prior to 0.54.0, jupyterlab-git uses fnmatch.fnmatchcase() in GitHandler.prepare() in jupyterlab_gi…

Fix: 0.54.0+
Fix from $1,950 2026-07-08
Jupyter Server MEDIUM 5.4
CVE-2026-44727

Jupyter Server is the backend for Jupyter web applications. Prior to 2.20, the nbconvert HTTP handlers in jupyter_server render user-authored noteboo…

Fix: 2.20.0+
Fix from $1,600 2026-06-22
Jupyter Server HIGH 8.8
CVE-2026-6657

A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation when the `allow_origin_pat` conf…

Fix: after 2.17.0
Fix from $1,950 2026-06-03
Jupyter Server HIGH 8.1
CVE-2026-5422

A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an incorrect root directory boundary check in the _get_os_path() functi…

No fix yet
Fix from $1,950 2026-06-02
Jupyterlab CRITICAL 9.6
CVE-2026-42557

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, Jupyt…

Fix: 4.5.7 / 7.5.6+
Fix from $2,300 2026-05-13
Jupyterlab HIGH 8.8
CVE-2026-42266

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, …

Fix: 4.5.7+
Fix from $1,950 2026-05-13
Jupyter Server HIGH 7.3
CVE-2026-40110

Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation uses Python's re.match() to …

Fix: 2.18.0+
Fix from $1,950 2026-05-05
Jupyter Server MEDIUM 6.8
CVE-2026-40934

Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign authentication cookies is persist…

Fix: 2.18.0+
Fix from $1,600 2026-05-05
Jupyter Server HIGH 8.8
CVE-2026-35397

Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an …

Fix: 2.18.0+
Fix from $1,950 2026-05-05
Jupyter Server MEDIUM 6.1
CVE-2025-61669

Jupyter Server is the backend for Jupyter web applications. In jupyter_server versions through 2.17.0, the next query parameter in the login flow is …

Fix: 2.18.0+
Fix from $1,600 2026-05-05
Nbconvert MEDIUM 6.5
CVE-2026-39378

The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. In versions 6.5 through 7.17.0, when …

Fix: 7.17.1+
Fix from $1,600 2026-04-21
Nbconvert MEDIUM 6.5
CVE-2026-39377

The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions 6.5 through 7.17.0 allow arb…

Fix: 7.17.1+
Fix from $1,600 2026-04-21
Lti Jupyterhub Authenticator MEDIUM 5.9
CVE-2026-34052

LTI JupyterHub Authenticator is a JupyterHub authenticator for LTI. Prior to version 1.6.3, the LTI 1.1 validator stores OAuth nonces in a class-leve…

Fix: 1.6.3+
Fix from $1,600 2026-04-03
Oauthenticator HIGH 8.8
CVE-2026-33175

OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authenticatio…

Fix: 17.4.0+
Fix from $1,950 2026-04-03
Jupyterhub MEDIUM 6.1
CVE-2026-33709

JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in…

Fix: 5.4.4+
Fix from $1,600 2026-04-03
Nbconvert HIGH 7.8
CVE-2025-53000

The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions of nbconvert up to and inclu…

Fix: after 7.16.6
Fix from $1,950 2025-12-17
Jupyter Core HIGH 7.3
CVE-2025-30167

Jupyter Core is a package for the core common functionality of Jupyter projects. When using Jupyter Core prior to version 5.8.0 on Windows, the share…

Fix: 5.8.0+
Fix from $1,950 2025-06-03
Lti Jupyterhub Authenticator CRITICAL 9.8
CVE-2023-25574

`jupyterhub-ltiauthenticator` is a JupyterHub authenticator for learning tools interoperability (LTI). LTI13Authenticator that was introduced in `jup…

Mitigation only
Fix from $2,300 2025-02-25
Jupyterlab MEDIUM 6.1
CVE-2024-43805

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. This vulnerability de…

Fix: 3.6.8 / 4.2.5+
Fix from $1,600 2024-08-28
Jupyterhub HIGH 7.2
CVE-2024-41942

JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted t…

Fix: 4.1.6+
Fix from $1,950 2024-08-08
Jupyterlab CRITICAL 9.8
CVE-2024-39700

JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include …

Fix: 4.3.0+
Fix from $2,300 2024-07-16
Jupyter Server Proxy MEDIUM 6.1
CVE-2024-35225

Jupyter Server Proxy allows users to run arbitrary external processes alongside their notebook server and provide authenticated web access to them. V…

Fix: 3.2.4 / 4.2.0+
Fix from $1,600 2024-06-11
Jupyter Server HIGH 7.5
CVE-2024-35178

The Jupyter Server provides the backend for Jupyter web applications. Jupyter Server on Windows has a vulnerability that lets unauthenticated attacke…

Fix: 2.14.1+
Fix from $1,950 2024-06-06
Jupyterhub MEDIUM 6.1
CVE-2024-28233

JupyterHub is an open source multi-user server for Jupyter notebooks. By tricking a user into visiting a malicious subdomain, the attacker can achiev…

Fix: 4.1.0+
Fix from $1,600 2024-03-27
Oauthenticator CRITICAL 9.1
CVE-2024-29033

OAuthenticator provides plugins for JupyterHub to use common OAuth providers, as well as base classes for writing one's own Authenticators with any O…

Fix: 16.3.0+
Fix from $2,300 2024-03-20
Jupyter Server Proxy CRITICAL 9.8
CVE-2024-28179

Jupyter Server Proxy allows users to run arbitrary external processes alongside their Jupyter notebook servers and provides authenticated web access.…

Fix: 3.2.3 / 4.1.1+
Fix from $2,300 2024-03-20