CVE-2026-22068
Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.X through 10
CVSS
8.2
High
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Jul 29, 2026 · Last modified: Jul 29, 2026 · CWE-777
Not enough EPSS history yet.
Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-401107.3 HIG26.6%
——8Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation uses Python's re.match() to check incoming origins against the allow_origin_pat configuration value. Because re.match() only anchors at the start of the string and does not require a full match, a pattern intended to match only a trusted domain (e.g., trusted.example.com) will also match any origin that begins with that domain followed by additional characters (e.g., trusted.example.com.evil.com). An attacker who controls such a domain can bypass the CORS origin restriction and make cross-origin requests to the Jupyter Server API from an untrusted site. This issue has been fixed in version 2.18.0.5dCVE-2026-390876.4 MED19.4%
——6ntfy before 2.22.0 allows SSRF because of an unanchored regular expression for web push endpoint URLs.25d