← Back
CWE-777

3 CVEs • Abstraction: Variant • Likelihood of Exploit: Medium

Regular Expression without Anchors

The product uses a regular expression to perform neutralization, but the regular expression is not anchored and may allow malicious or malformed data to slip through.

JSON object

Loading...

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 24, 2026
Jun 18, 2026
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
Webmin allows unauthenticated attackers to read the contents of any file ending in .conf within module directories, due to a bypassable regex pattern.
1Jupyter
1Jupyter Server
Jul 24, 2026
May 5, 2026
7.6 HIGH· v4
7.3 HIGH· v3
N/A· v2
Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation uses Python's re.match() to check incoming origins against the allow_origin_pat configuration value...Show more
Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation uses Python's re.match() to check incoming origins against the allow_origin_pat configuration value. Because re.match() only anchors at the start of the string and does not require a full match, a pattern intended to match only a trusted domain (e.g., trusted.example.com) will also match any origin that begins with that domain followed by additional characters (e.g., trusted.example.com.evil.com). An attacker who controls such a domain can bypass the CORS origin restriction and make cross-origin requests to the Jupyter Server API from an untrusted site. This issue has been fixed in version 2.18.0.Show less
-
-
Jul 4, 2026
Apr 23, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
ntfy before 2.22.0 allows SSRF because of an unanchored regular expression for web push endpoint URLs.