#1150003 jupyter-server: CVE-2026-86049

Package:
src:jupyter-server
Source:
src:jupyter-server
Submitter:
Salvatore Bonaccorso
Date:
2026-10-05 05:53:05 UTC
Severity:
normal
Tags:
#1150003#5
Date:
2026-10-05 05:52:16 UTC
From:
To:
Hi,

The following vulnerability was published for jupyter-server.

CVE-2026-86049[0]:
| Jupyter Server is the backend for Jupyter web applications. Prior to
| version 2.21.0, the 5xx request logging path in
| jupyter_server/log.py copies the Referer header into a JSON header
| block without applying the token scrubbing used for the request URI.
| A request that returns HTTP 500 while the Referer contains a token-
| bearing URL can therefore write that token to server logs in
| plaintext. An attacker who can read those logs can recover the token
| and use the affected user's Jupyter Server permissions. This issue
| is fixed in version 2.21.0.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-86049
https://www.cve.org/CVERecord?id=CVE-2026-86049
[1] https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-c3mw-737p-c7g2
[2] https://github.com/jupyter-server/jupyter_server/pull/1681

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore