Bokeh is a Python visualization library whose vulnerability footprint centers on its interactive web-based charting and dashboard capabilities. The durable signal reflects the product's WebSocket-based real-time communication architecture, with observed exposure centered on origin-validation weaknesses in these socket interactions that can undermine cross-origin protections. Live severity, exploitation, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bokeh over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-21883MEDIUM Bokeh is an interactive visualization library written in Python. In versions 3.8.1 and below, if a server is configured with an allowlist (e.g., dashboard.corp), an attacker can re | Jan 8, 2026 | 5.4 | 21 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bokeh.
Media articles that mention a CVE ID that affects a product developed by Bokeh — matched by CVE ID, not by vendor name.