Hi,
The following vulnerability was published for jupyter-server.
CVE-2026-86049[0]:
| Jupyter Server is the backend for Jupyter web applications. Prior to
| version 2.21.0, the 5xx request logging path in
| jupyter_server/log.py copies the Referer header into a JSON header
| block without applying the token scrubbing used for the request URI.
| A request that returns HTTP 500 while the Referer contains a token-
| bearing URL can therefore write that token to server logs in
| plaintext. An attacker who can read those logs can recover the token
| and use the affected user's Jupyter Server permissions. This issue
| is fixed in version 2.21.0.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-86049
https://www.cve.org/CVERecord?id=CVE-2026-86049
[1] https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-c3mw-737p-c7g2
[2] https://github.com/jupyter-server/jupyter_server/pull/1681
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore