5.4
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
Description
CVE-2026-40864 — JupyterHub XSRF bypass via cross-origin form POST Sec-Fetch-Mode: no-cors Severity: Moderate CWE: CWE-352 — Cross-Site Request Forgery XSRF Affected: jupyterhub 4.1.0 ≤ version posting to a different origin — precisely the classic CSRF...
Basic Information
ID
6DC85E25-562C-5013-9637-8ECC82BB80F9
Published
Jun 13, 2026 at 07:11