cbcvebase.

Jupyter Enterprise Gateway vulnerabilities

3 known vulnerabilities affecting jupyter/enterprise_gateway.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3

Vulnerabilities

Page 1 of 1
CVE-2026-44181P2CRITICALCVSS 10.0≥ 2.1.0, < 3.3.0v2.0.0+1 more2026-07-16
CVE-2026-44181 [CRITICAL] CWE-1336 CVE-2026-44181: Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In versions 2.0.0rc2 and above, prior to 3.3.0, the environment variables (KERNEL_XXX) used during the rendering of the Kubernetes manifest are vulnerable to Server Side Template Injection (SSTI). By inc
nvd
CVE-2026-44182P2CRITICALCVSS 10.0fixed in 3.3.02026-07-16
CVE-2026-44182 [CRITICAL] CWE-74 CVE-2026-44182: Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In versions prior to 3.3.0, the server interpolates untrusted environment variables (e.g., KERNEL_XXX) into Kubernetes manifests without YAML-aware escaping, enabling YAML injection attacks. Attackers can
nvd
CVE-2026-44180P2CRITICALCVSS 9.8≥ 2.1.0, < 3.3.0v2.0.0+2 more2026-07-16
CVE-2026-44180 [CRITICAL] CWE-20 CVE-2026-44180: Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. Versions 2.0.0rc1 and above prior to 3.3.0 have a prohibited UID and GID feature that by default prevents launching kernels with UID or GID 0 (root), and this restriction can be bypassed using a specially
nvd
Jupyter Enterprise Gateway vulnerabilities | cvebase