Known Vulnerabilities for products from Jupyter

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Jupyter".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-39378 json The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. In versions 6... Not Provided 2026-04-21 2026-04-23
CVE-2026-39377 json The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions 6.5 ... Not Provided 2026-04-21 2026-04-23
CVE-2026-34052 json LTI JupyterHub Authenticator is a JupyterHub authenticator for LTI. Prior to version 1.6.3, the LTI 1.1 validator stores OAut... Not Provided 2026-04-03 2026-04-13
CVE-2026-33709 json JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open r... Not Provided 2026-04-03 2026-04-22
CVE-2026-33175 json OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version ... Not Provided 2026-04-03 2026-04-15
CVE-2024-22421 json 6.5 - MEDIUM 2024-01-19 2024-02-02
CVE-2024-22420 json 6.1 - MEDIUM 2024-01-19 2024-02-02
CVE-2024-22415 json 9.8 - CRITICAL 2024-01-18 2024-01-30
CVE-2023-49080 json 4.3 - MEDIUM 2023-12-04 2023-12-07
CVE-2023-40170 json jupyter-server is the backend for Jupyter web applications. Improper cross-site credential checks on `/files/` URLs could all... 6.1 - MEDIUM 2023-08-28 2023-09-15
CVE-2023-39968 json jupyter-server is the backend for Jupyter web applications. Open Redirect Vulnerability. Maliciously crafted login links to k... 6.1 - MEDIUM 2023-08-28 2023-09-15
CVE-2022-39286 json Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contain... 8.8 - HIGH 2022-10-26 2023-11-07
CVE-2022-31027 json OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthentic... 6.5 - MEDIUM 2022-06-09 2022-06-16
CVE-2022-29241 json Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupy... 8.8 - HIGH 2022-06-14 2022-06-24
CVE-2022-29238 json Jupyter Notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.12, authenticated reques... 4.3 - MEDIUM 2022-06-14 2022-06-24
CVE-2022-24758 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 7.5 - HIGH 2022-03-31 2022-04-08
CVE-2022-24757 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 7.5 - HIGH 2022-03-23 2022-04-04
CVE-2022-21697 json Jupyter Server Proxy is a Jupyter notebook server extension to proxy web services. Versions of Jupyter Server Proxy prior to ... 7.1 - HIGH 2022-01-25 2022-02-01
CVE-2021-41247 json JupyterHub is an open source multi-user server for Jupyter notebooks. In affected versions users who have multiple JupyterLab... 7.5 - HIGH 2021-11-04 2021-11-10
CVE-2021-41134 json nbdime provides tools for diffing and merging of Jupyter Notebooks. In affected versions a stored cross-site scripting (XSS) ... 5.4 - MEDIUM 2021-11-03 2021-11-05

Known software with vulnerabilities from Jupyter

Type Vendor Product Version
ApplicationJupyterJupyterhub0.1.0
ApplicationJupyterJupyter Server0.0.1
ApplicationJupyterNotebook4.0.0
ApplicationJupyterOauthenticator0.1.0