1. Bokeh Server Security Flaw: CVE-2026-21883 Exposes Deployed Instances to WebSocket Hijacking
A critical security vulnerability, CVE-2026-21883, has been disclosed in the Bokeh data visualization library, exposing deployed server instances to Cross-Site WebSocket Hijacking (CSWSH). The flaw, which prompted an automated dependency update from version 2.4.3 to 3.8.2, allows attackers to hijack WebSocket connectio...