[Git][security-tracker-team/security-tracker][master] jupyter-server fixed in sid

Moritz Muehlenhoff (@jmm) jmm at debian.org
Tue Jun 23 14:36:46 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
3ecd8030 by Moritz Muehlenhoff at 2026-06-23T15:35:52+02:00
jupyter-server fixed in sid

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -32961,7 +32961,7 @@ CVE-2026-44331 (In ProFTPD through 1.3.9a before 7666224, a SQL injection vulner
 CVE-2026-41950 (Dify before version 1.14.0 contains an authorization bypass vulnerabil ...)
 	NOT-FOR-US: Dify
 CVE-2026-40934 (Jupyter Server is the backend for Jupyter web applications. In version ...)
-	- jupyter-server <unfixed> (bug #1136022)
+	- jupyter-server 2.20.0-1 (bug #1136022)
 	NOTE: https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-5mrq-x3x5-8v8f
 CVE-2026-40331 (Masa CMS is an open source content management system. In versions 7.2. ...)
 	NOT-FOR-US: Masa CMS
@@ -32972,7 +32972,7 @@ CVE-2026-40329 (Masa CMS is an open source content management system. In version
 CVE-2026-40280 (Gotenberg is an API-based document conversion tool. In versions 8.30.1 ...)
 	NOT-FOR-US: Gotenberg
 CVE-2026-40110 (Jupyter Server is the backend for Jupyter web applications. In version ...)
-	- jupyter-server <unfixed> (bug #1136022)
+	- jupyter-server 2.20.0-1 (bug #1136022)
 	NOTE: https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-24qx-w28j-9m6p
 	NOTE: https://github.com/jupyter-server/jupyter_server/pull/603
 	NOTE: https://github.com/jupyter-server/jupyter_server/commit/057869a327c46730afede3eab0ca2d2e3e74acea (v2.18.0)
@@ -32994,7 +32994,7 @@ CVE-2026-35579 (CoreDNS is a DNS server written in Go. In versions prior to 1.14
 CVE-2026-35453 (PhpSpreadsheet is a library for reading and writing spreadsheet files. ...)
 	NOT-FOR-US: PhpSpreadsheet
 CVE-2026-35397 (Jupyter Server is the backend for Jupyter web applications. In version ...)
-	- jupyter-server <unfixed> (bug #1136022)
+	- jupyter-server 2.20.0-1 (bug #1136022)
 	NOTE: https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-5789-5fc7-67v3
 CVE-2026-34596 (Sandboxie-Plus is an open source sandbox-based isolation software for  ...)
 	NOT-FOR-US: Sandboxie-Plus
@@ -33257,7 +33257,7 @@ CVE-2026-23479 (Redis is an in-memory data structure store. In redis-server from
 CVE-2025-66369 (An issue was discovered in MM in Samsung Mobile Processor, Wearable Pr ...)
 	NOT-FOR-US: Samsung
 CVE-2025-61669 (Jupyter Server is the backend for Jupyter web applications. In jupyter ...)
-	- jupyter-server <unfixed> (bug #1136022)
+	- jupyter-server 2.20.0-1 (bug #1136022)
 	NOTE: https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-qh7q-6qm3-653w
 CVE-2025-52206 (ISPConfig 3.3.0 is vulnerable to Cross Site Scripting (XSS) via the sy ...)
 	NOT-FOR-US: ISPConfig



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3ecd803030c00230198a405f0661c9e1abed8ad8

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3ecd803030c00230198a405f0661c9e1abed8ad8
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260623/0142a7eb/attachment.htm>


More information about the debian-security-tracker-commits mailing list