[Git][security-tracker-team/security-tracker][master] Add new jupyter-server issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed May 6 08:29:41 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
f6a5e856 by Salvatore Bonaccorso at 2026-05-06T09:29:21+02:00
Add new jupyter-server issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -18,7 +18,8 @@ CVE-2026-44331 (In ProFTPD through 1.3.9a before 7666224, a SQL injection vulner
 CVE-2026-41950 (Dify before version 1.14.0 contains an authorization bypass vulnerabil ...)
 	NOT-FOR-US: Dify
 CVE-2026-40934 (Jupyter Server is the backend for Jupyter web applications. In version ...)
-	TODO: check
+	- jupyter-server <unfixed>
+	NOTE: https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-5mrq-x3x5-8v8f
 CVE-2026-40331 (Masa CMS is an open source content management system. In versions 7.2. ...)
 	NOT-FOR-US: Masa CMS
 CVE-2026-40330 (Masa CMS is an open source content management system. In versions 7.2. ...)
@@ -28,7 +29,11 @@ CVE-2026-40329 (Masa CMS is an open source content management system. In version
 CVE-2026-40280 (Gotenberg is an API-based document conversion tool. In versions 8.30.1 ...)
 	NOT-FOR-US: Gotenberg
 CVE-2026-40110 (Jupyter Server is the backend for Jupyter web applications. In version ...)
-	TODO: check
+	- jupyter-server <unfixed>
+	NOTE: https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-24qx-w28j-9m6p
+	NOTE: https://github.com/jupyter-server/jupyter_server/pull/603
+	NOTE: https://github.com/jupyter-server/jupyter_server/commit/057869a327c46730afede3eab0ca2d2e3e74acea (v2.18.0)
+	NOTE: https://github.com/jupyter-server/jupyter_server/commit/49b34392feaa97735b3b777e3baf8f22f2a14ed8 (v2.18.0)
 CVE-2026-40075 (OpenMRS Core is an open source electronic medical record system platfo ...)
 	NOT-FOR-US: OpenMRS
 CVE-2026-40068 (In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust det ...)
@@ -46,7 +51,8 @@ CVE-2026-35579 (CoreDNS is a DNS server written in Go. In versions prior to 1.14
 CVE-2026-35453 (PhpSpreadsheet is a library for reading and writing spreadsheet files. ...)
 	NOT-FOR-US: PhpSpreadsheet
 CVE-2026-35397 (Jupyter Server is the backend for Jupyter web applications. In version ...)
-	TODO: check
+	- jupyter-server <unfixed>
+	NOTE: https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-5789-5fc7-67v3
 CVE-2026-34596 (Sandboxie-Plus is an open source sandbox-based isolation software for  ...)
 	NOT-FOR-US: Sandboxie-Plus
 CVE-2026-34527 (Sandboxie-Plus is an open source sandbox-based isolation software for  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f6a5e85653786f68967c1846e7897355f0c7f944

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f6a5e85653786f68967c1846e7897355f0c7f944
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260506/5b8aeafc/attachment.htm>


More information about the debian-security-tracker-commits mailing list