highCVSS 7.1Vulnerability

CVE-2026-86049

### Summary When a request returns a 500, `jupyter_server/log.py` logs a small JSON block of request headers. The Referer header was copied into it as-is, so a token in the Referer URL ended up in the logs in plain text. ### Impact Anyone who can read the server logs can pick tokens out of these 500 entries. Tokens end up in the Referer during normal token-based login and launch flows. Affected: all versions before 2.21.0. ### PoC Any malformed request that returns a 500 works: ```bash curl -i -X POST \ -H 'Content-Type: application/json' \ -H 'Referer: http://127.0.0.1:8899/tree?token=REFERTOKEN' \ --data '{"name":123}' \ 'http://127.0.0.1:8899/api/kernels?token=VALIDTOKEN' ``` The log shows the token twice, once raw and once redacted: ``` "Referer": "http://127.0.0.1:8899/tree?token=REFERTOKEN", [E ... ServerApp] 500 POST /api/kernels?token=[secret] (...) referer=http://127.0.0.1:8899/tree?token=[secret] ``` ### Patches Fixed in 2.21.0 by 5251352. Header values are now scrubbed before the block is logged. Upgrade to 2.21.0 or later. ### Workarounds Limit who can read the server logs. If you can, avoid flows that put the token in the URL.

Properties

ghsa_id
GHSA-c3mw-737p-c7g2
summary
Jupyter Server: 5xx request logging leaks token-bearing Referer header values
severity
high
cvss_score
7.1
cve_id
CVE-2026-86049
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
signal_observed_at
2026-09-17T21:32:39+00:00
is_ghsa_only
false
ghsa_published
2026-09-17T20:28:55Z
source_url
https://github.com/advisories/GHSA-c3mw-737p-c7g2
ghsa_updated
2026-09-17T20:28:57Z

Related Entities (4)

HAS_WEAKNESS (1)

[Weakness]Insertion of Sensitive Information into Log File

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]pip/jupyter_server

AFFECTS (1)

[Software]pip/jupyter_server

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-86049 (CVSS 7.1) — Ninja Signal Threat Intelligence | Ninja Signal