jupyterhub
Multi-user server for Jupyter notebooks
Activity
- Latest release
- 17h ago
- Total releases
- 104
- Cadence
- ~17 days
- Last 12 months
- 15
Reach
- Stars
- 8.3k
Details
- License
- BSD-3-Clause
- First release
- Mar 08, 2015
| Version | Released | |
|---|---|---|
6.0.1
patch
| ||
6.0.0
major
| ||
5.5.2
patch
| ||
6.0.0b3
pre
| ||
6.0.0b2
pre
| ||
6.0.0b1
pre
| ||
5.5.1
patch
| ||
5.5.0
minor
| ||
5.4.6
patch
1 CVE
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
5.4.5
patch
1 CVE
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
5.4.4
patch
2 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-40864
PYSEC-2026-2189
BIT-jupyterhub-2026-40864
GHSA-m68r-v472-jgq9
May 22, 2026
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF protection (updated in 4.1.0) inappropriately treated requests with Sec-Fetch-Mode: no-cors as same-origin requests, bypassing XSRF checks. The JSON API is not affected, only HTTP form endpoints, such as /hub/spawn and /hub/accept-share, meaning attackers could trigger server spawn (but not access the server) and if the attacker is a JupyterHub user permitted to share access to their server, cause a user to accept a share and have access to the attacker's server. This issue has been fixed in version 5.4.5. If developers are unable to immediately upgrade, they can temporarily mitigate this issue by dropping requests to JupyterHub with Sec-Fetch-Mode: no-cors if they are using a reverse proxy. Affected versions
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
+ 8 more Show less
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
Fixed in
5.4.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
5.4.3
patch
3 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-40864
PYSEC-2026-2189
BIT-jupyterhub-2026-40864
GHSA-m68r-v472-jgq9
May 22, 2026
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF protection (updated in 4.1.0) inappropriately treated requests with Sec-Fetch-Mode: no-cors as same-origin requests, bypassing XSRF checks. The JSON API is not affected, only HTTP form endpoints, such as /hub/spawn and /hub/accept-share, meaning attackers could trigger server spawn (but not access the server) and if the attacker is a JupyterHub user permitted to share access to their server, cause a user to accept a share and have access to the attacker's server. This issue has been fixed in version 5.4.5. If developers are unable to immediately upgrade, they can temporarily mitigate this issue by dropping requests to JupyterHub with Sec-Fetch-Mode: no-cors if they are using a reverse proxy. Affected versions
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
+ 8 more Show less
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
Fixed in
5.4.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev | ||
5.4.2
patch
3 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-40864
PYSEC-2026-2189
BIT-jupyterhub-2026-40864
GHSA-m68r-v472-jgq9
May 22, 2026
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF protection (updated in 4.1.0) inappropriately treated requests with Sec-Fetch-Mode: no-cors as same-origin requests, bypassing XSRF checks. The JSON API is not affected, only HTTP form endpoints, such as /hub/spawn and /hub/accept-share, meaning attackers could trigger server spawn (but not access the server) and if the attacker is a JupyterHub user permitted to share access to their server, cause a user to accept a share and have access to the attacker's server. This issue has been fixed in version 5.4.5. If developers are unable to immediately upgrade, they can temporarily mitigate this issue by dropping requests to JupyterHub with Sec-Fetch-Mode: no-cors if they are using a reverse proxy. Affected versions
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
+ 8 more Show less
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
Fixed in
5.4.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev | ||
5.4.1
patch
3 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-40864
PYSEC-2026-2189
BIT-jupyterhub-2026-40864
GHSA-m68r-v472-jgq9
May 22, 2026
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF protection (updated in 4.1.0) inappropriately treated requests with Sec-Fetch-Mode: no-cors as same-origin requests, bypassing XSRF checks. The JSON API is not affected, only HTTP form endpoints, such as /hub/spawn and /hub/accept-share, meaning attackers could trigger server spawn (but not access the server) and if the attacker is a JupyterHub user permitted to share access to their server, cause a user to accept a share and have access to the attacker's server. This issue has been fixed in version 5.4.5. If developers are unable to immediately upgrade, they can temporarily mitigate this issue by dropping requests to JupyterHub with Sec-Fetch-Mode: no-cors if they are using a reverse proxy. Affected versions
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
+ 8 more Show less
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
Fixed in
5.4.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev | ||
5.4.0
minor
3 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-40864
PYSEC-2026-2189
BIT-jupyterhub-2026-40864
GHSA-m68r-v472-jgq9
May 22, 2026
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF protection (updated in 4.1.0) inappropriately treated requests with Sec-Fetch-Mode: no-cors as same-origin requests, bypassing XSRF checks. The JSON API is not affected, only HTTP form endpoints, such as /hub/spawn and /hub/accept-share, meaning attackers could trigger server spawn (but not access the server) and if the attacker is a JupyterHub user permitted to share access to their server, cause a user to accept a share and have access to the attacker's server. This issue has been fixed in version 5.4.5. If developers are unable to immediately upgrade, they can temporarily mitigate this issue by dropping requests to JupyterHub with Sec-Fetch-Mode: no-cors if they are using a reverse proxy. Affected versions
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
+ 8 more Show less
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
Fixed in
5.4.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev | ||
5.3.0
minor
3 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-40864
PYSEC-2026-2189
BIT-jupyterhub-2026-40864
GHSA-m68r-v472-jgq9
May 22, 2026
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF protection (updated in 4.1.0) inappropriately treated requests with Sec-Fetch-Mode: no-cors as same-origin requests, bypassing XSRF checks. The JSON API is not affected, only HTTP form endpoints, such as /hub/spawn and /hub/accept-share, meaning attackers could trigger server spawn (but not access the server) and if the attacker is a JupyterHub user permitted to share access to their server, cause a user to accept a share and have access to the attacker's server. This issue has been fixed in version 5.4.5. If developers are unable to immediately upgrade, they can temporarily mitigate this issue by dropping requests to JupyterHub with Sec-Fetch-Mode: no-cors if they are using a reverse proxy. Affected versions
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
+ 8 more Show less
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
Fixed in
5.4.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev | ||
5.3.0rc0
pre
3 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-40864
PYSEC-2026-2189
BIT-jupyterhub-2026-40864
GHSA-m68r-v472-jgq9
May 22, 2026
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF protection (updated in 4.1.0) inappropriately treated requests with Sec-Fetch-Mode: no-cors as same-origin requests, bypassing XSRF checks. The JSON API is not affected, only HTTP form endpoints, such as /hub/spawn and /hub/accept-share, meaning attackers could trigger server spawn (but not access the server) and if the attacker is a JupyterHub user permitted to share access to their server, cause a user to accept a share and have access to the attacker's server. This issue has been fixed in version 5.4.5. If developers are unable to immediately upgrade, they can temporarily mitigate this issue by dropping requests to JupyterHub with Sec-Fetch-Mode: no-cors if they are using a reverse proxy. Affected versions
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
+ 8 more Show less
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
Fixed in
5.4.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev | ||
5.2.1
patch
3 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-40864
PYSEC-2026-2189
BIT-jupyterhub-2026-40864
GHSA-m68r-v472-jgq9
May 22, 2026
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF protection (updated in 4.1.0) inappropriately treated requests with Sec-Fetch-Mode: no-cors as same-origin requests, bypassing XSRF checks. The JSON API is not affected, only HTTP form endpoints, such as /hub/spawn and /hub/accept-share, meaning attackers could trigger server spawn (but not access the server) and if the attacker is a JupyterHub user permitted to share access to their server, cause a user to accept a share and have access to the attacker's server. This issue has been fixed in version 5.4.5. If developers are unable to immediately upgrade, they can temporarily mitigate this issue by dropping requests to JupyterHub with Sec-Fetch-Mode: no-cors if they are using a reverse proxy. Affected versions
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
+ 8 more Show less
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
Fixed in
5.4.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev | ||
5.2.0
minor
3 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-40864
PYSEC-2026-2189
BIT-jupyterhub-2026-40864
GHSA-m68r-v472-jgq9
May 22, 2026
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF protection (updated in 4.1.0) inappropriately treated requests with Sec-Fetch-Mode: no-cors as same-origin requests, bypassing XSRF checks. The JSON API is not affected, only HTTP form endpoints, such as /hub/spawn and /hub/accept-share, meaning attackers could trigger server spawn (but not access the server) and if the attacker is a JupyterHub user permitted to share access to their server, cause a user to accept a share and have access to the attacker's server. This issue has been fixed in version 5.4.5. If developers are unable to immediately upgrade, they can temporarily mitigate this issue by dropping requests to JupyterHub with Sec-Fetch-Mode: no-cors if they are using a reverse proxy. Affected versions
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
+ 8 more Show less
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
Fixed in
5.4.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev | ||
5.1.0
minor
3 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-40864
PYSEC-2026-2189
BIT-jupyterhub-2026-40864
GHSA-m68r-v472-jgq9
May 22, 2026
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF protection (updated in 4.1.0) inappropriately treated requests with Sec-Fetch-Mode: no-cors as same-origin requests, bypassing XSRF checks. The JSON API is not affected, only HTTP form endpoints, such as /hub/spawn and /hub/accept-share, meaning attackers could trigger server spawn (but not access the server) and if the attacker is a JupyterHub user permitted to share access to their server, cause a user to accept a share and have access to the attacker's server. This issue has been fixed in version 5.4.5. If developers are unable to immediately upgrade, they can temporarily mitigate this issue by dropping requests to JupyterHub with Sec-Fetch-Mode: no-cors if they are using a reverse proxy. Affected versions
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
+ 8 more Show less
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
Fixed in
5.4.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev | ||
4.1.6
patch
3 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-40864
PYSEC-2026-2189
BIT-jupyterhub-2026-40864
GHSA-m68r-v472-jgq9
May 22, 2026
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF protection (updated in 4.1.0) inappropriately treated requests with Sec-Fetch-Mode: no-cors as same-origin requests, bypassing XSRF checks. The JSON API is not affected, only HTTP form endpoints, such as /hub/spawn and /hub/accept-share, meaning attackers could trigger server spawn (but not access the server) and if the attacker is a JupyterHub user permitted to share access to their server, cause a user to accept a share and have access to the attacker's server. This issue has been fixed in version 5.4.5. If developers are unable to immediately upgrade, they can temporarily mitigate this issue by dropping requests to JupyterHub with Sec-Fetch-Mode: no-cors if they are using a reverse proxy. Affected versions
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
+ 8 more Show less
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
Fixed in
5.4.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev | ||
5.0.0
major
3 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-40864
PYSEC-2026-2189
BIT-jupyterhub-2026-40864
GHSA-m68r-v472-jgq9
May 22, 2026
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF protection (updated in 4.1.0) inappropriately treated requests with Sec-Fetch-Mode: no-cors as same-origin requests, bypassing XSRF checks. The JSON API is not affected, only HTTP form endpoints, such as /hub/spawn and /hub/accept-share, meaning attackers could trigger server spawn (but not access the server) and if the attacker is a JupyterHub user permitted to share access to their server, cause a user to accept a share and have access to the attacker's server. This issue has been fixed in version 5.4.5. If developers are unable to immediately upgrade, they can temporarily mitigate this issue by dropping requests to JupyterHub with Sec-Fetch-Mode: no-cors if they are using a reverse proxy. Affected versions
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
+ 8 more Show less
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
Fixed in
5.4.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev | ||
5.0.0b2
pre
3 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-40864
PYSEC-2026-2189
BIT-jupyterhub-2026-40864
GHSA-m68r-v472-jgq9
May 22, 2026
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF protection (updated in 4.1.0) inappropriately treated requests with Sec-Fetch-Mode: no-cors as same-origin requests, bypassing XSRF checks. The JSON API is not affected, only HTTP form endpoints, such as /hub/spawn and /hub/accept-share, meaning attackers could trigger server spawn (but not access the server) and if the attacker is a JupyterHub user permitted to share access to their server, cause a user to accept a share and have access to the attacker's server. This issue has been fixed in version 5.4.5. If developers are unable to immediately upgrade, they can temporarily mitigate this issue by dropping requests to JupyterHub with Sec-Fetch-Mode: no-cors if they are using a reverse proxy. Affected versions
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
+ 8 more Show less
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
Fixed in
5.4.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev | ||
5.0.0b1
pre
3 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-40864
PYSEC-2026-2189
BIT-jupyterhub-2026-40864
GHSA-m68r-v472-jgq9
May 22, 2026
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF protection (updated in 4.1.0) inappropriately treated requests with Sec-Fetch-Mode: no-cors as same-origin requests, bypassing XSRF checks. The JSON API is not affected, only HTTP form endpoints, such as /hub/spawn and /hub/accept-share, meaning attackers could trigger server spawn (but not access the server) and if the attacker is a JupyterHub user permitted to share access to their server, cause a user to accept a share and have access to the attacker's server. This issue has been fixed in version 5.4.5. If developers are unable to immediately upgrade, they can temporarily mitigate this issue by dropping requests to JupyterHub with Sec-Fetch-Mode: no-cors if they are using a reverse proxy. Affected versions
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
+ 8 more Show less
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
Fixed in
5.4.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev | ||
4.1.5
patch
4 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-40864
PYSEC-2026-2189
BIT-jupyterhub-2026-40864
GHSA-m68r-v472-jgq9
May 22, 2026
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF protection (updated in 4.1.0) inappropriately treated requests with Sec-Fetch-Mode: no-cors as same-origin requests, bypassing XSRF checks. The JSON API is not affected, only HTTP form endpoints, such as /hub/spawn and /hub/accept-share, meaning attackers could trigger server spawn (but not access the server) and if the attacker is a JupyterHub user permitted to share access to their server, cause a user to accept a share and have access to the attacker's server. This issue has been fixed in version 5.4.5. If developers are unable to immediately upgrade, they can temporarily mitigate this issue by dropping requests to JupyterHub with Sec-Fetch-Mode: no-cors if they are using a reverse proxy. Affected versions
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
+ 8 more Show less
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
Fixed in
5.4.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-41942
PYSEC-2024-200
BIT-jupyterhub-2024-41942
GHSA-9x4q-3gxw-849f
Aug 08, 2024
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 68 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
Fixed in
4.1.6
References Updated Jan 19, 2025 · Source: OSV.dev | ||
4.1.4
patch
4 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-40864
PYSEC-2026-2189
BIT-jupyterhub-2026-40864
GHSA-m68r-v472-jgq9
May 22, 2026
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF protection (updated in 4.1.0) inappropriately treated requests with Sec-Fetch-Mode: no-cors as same-origin requests, bypassing XSRF checks. The JSON API is not affected, only HTTP form endpoints, such as /hub/spawn and /hub/accept-share, meaning attackers could trigger server spawn (but not access the server) and if the attacker is a JupyterHub user permitted to share access to their server, cause a user to accept a share and have access to the attacker's server. This issue has been fixed in version 5.4.5. If developers are unable to immediately upgrade, they can temporarily mitigate this issue by dropping requests to JupyterHub with Sec-Fetch-Mode: no-cors if they are using a reverse proxy. Affected versions
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
+ 8 more Show less
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
Fixed in
5.4.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-41942
PYSEC-2024-200
BIT-jupyterhub-2024-41942
GHSA-9x4q-3gxw-849f
Aug 08, 2024
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 68 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
Fixed in
4.1.6
References Updated Jan 19, 2025 · Source: OSV.dev | ||
4.1.3
patch
4 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-40864
PYSEC-2026-2189
BIT-jupyterhub-2026-40864
GHSA-m68r-v472-jgq9
May 22, 2026
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF protection (updated in 4.1.0) inappropriately treated requests with Sec-Fetch-Mode: no-cors as same-origin requests, bypassing XSRF checks. The JSON API is not affected, only HTTP form endpoints, such as /hub/spawn and /hub/accept-share, meaning attackers could trigger server spawn (but not access the server) and if the attacker is a JupyterHub user permitted to share access to their server, cause a user to accept a share and have access to the attacker's server. This issue has been fixed in version 5.4.5. If developers are unable to immediately upgrade, they can temporarily mitigate this issue by dropping requests to JupyterHub with Sec-Fetch-Mode: no-cors if they are using a reverse proxy. Affected versions
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
+ 8 more Show less
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
Fixed in
5.4.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-41942
PYSEC-2024-200
BIT-jupyterhub-2024-41942
GHSA-9x4q-3gxw-849f
Aug 08, 2024
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 68 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
Fixed in
4.1.6
References Updated Jan 19, 2025 · Source: OSV.dev | ||
4.1.2
patch
4 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-40864
PYSEC-2026-2189
BIT-jupyterhub-2026-40864
GHSA-m68r-v472-jgq9
May 22, 2026
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF protection (updated in 4.1.0) inappropriately treated requests with Sec-Fetch-Mode: no-cors as same-origin requests, bypassing XSRF checks. The JSON API is not affected, only HTTP form endpoints, such as /hub/spawn and /hub/accept-share, meaning attackers could trigger server spawn (but not access the server) and if the attacker is a JupyterHub user permitted to share access to their server, cause a user to accept a share and have access to the attacker's server. This issue has been fixed in version 5.4.5. If developers are unable to immediately upgrade, they can temporarily mitigate this issue by dropping requests to JupyterHub with Sec-Fetch-Mode: no-cors if they are using a reverse proxy. Affected versions
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
+ 8 more Show less
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
Fixed in
5.4.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-41942
PYSEC-2024-200
BIT-jupyterhub-2024-41942
GHSA-9x4q-3gxw-849f
Aug 08, 2024
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 68 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
Fixed in
4.1.6
References Updated Jan 19, 2025 · Source: OSV.dev | ||
4.1.1
patch
4 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-40864
PYSEC-2026-2189
BIT-jupyterhub-2026-40864
GHSA-m68r-v472-jgq9
May 22, 2026
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF protection (updated in 4.1.0) inappropriately treated requests with Sec-Fetch-Mode: no-cors as same-origin requests, bypassing XSRF checks. The JSON API is not affected, only HTTP form endpoints, such as /hub/spawn and /hub/accept-share, meaning attackers could trigger server spawn (but not access the server) and if the attacker is a JupyterHub user permitted to share access to their server, cause a user to accept a share and have access to the attacker's server. This issue has been fixed in version 5.4.5. If developers are unable to immediately upgrade, they can temporarily mitigate this issue by dropping requests to JupyterHub with Sec-Fetch-Mode: no-cors if they are using a reverse proxy. Affected versions
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
+ 8 more Show less
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
Fixed in
5.4.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-41942
PYSEC-2024-200
BIT-jupyterhub-2024-41942
GHSA-9x4q-3gxw-849f
Aug 08, 2024
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 68 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
Fixed in
4.1.6
References Updated Jan 19, 2025 · Source: OSV.dev | ||
4.1.0
minor
4 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-40864
PYSEC-2026-2189
BIT-jupyterhub-2026-40864
GHSA-m68r-v472-jgq9
May 22, 2026
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF protection (updated in 4.1.0) inappropriately treated requests with Sec-Fetch-Mode: no-cors as same-origin requests, bypassing XSRF checks. The JSON API is not affected, only HTTP form endpoints, such as /hub/spawn and /hub/accept-share, meaning attackers could trigger server spawn (but not access the server) and if the attacker is a JupyterHub user permitted to share access to their server, cause a user to accept a share and have access to the attacker's server. This issue has been fixed in version 5.4.5. If developers are unable to immediately upgrade, they can temporarily mitigate this issue by dropping requests to JupyterHub with Sec-Fetch-Mode: no-cors if they are using a reverse proxy. Affected versions
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
+ 8 more Show less
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
Fixed in
5.4.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-41942
PYSEC-2024-200
BIT-jupyterhub-2024-41942
GHSA-9x4q-3gxw-849f
Aug 08, 2024
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 68 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
Fixed in
4.1.6
References Updated Jan 19, 2025 · Source: OSV.dev | ||
4.0.2
patch
4 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-28233
PYSEC-2026-1480
BIT-jupyterhub-2024-28233
GHSA-7r3h-4ph8-w38g
Jul 07, 2026
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
ImpactAffected configurations:
By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS directly affecting the former's session. More precisely, in the context of JupyterHub, this XSS could achieve the following:
PatchesTo prevent cookie-tossing:
or, if available (applies to earlier JupyterHub versions):
Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 62 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
Fixed in
4.1.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-41942
PYSEC-2024-200
BIT-jupyterhub-2024-41942
GHSA-9x4q-3gxw-849f
Aug 08, 2024
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 68 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
Fixed in
4.1.6
References Updated Jan 19, 2025 · Source: OSV.dev | ||
4.0.1
patch
4 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-28233
PYSEC-2026-1480
BIT-jupyterhub-2024-28233
GHSA-7r3h-4ph8-w38g
Jul 07, 2026
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
ImpactAffected configurations:
By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS directly affecting the former's session. More precisely, in the context of JupyterHub, this XSS could achieve the following:
PatchesTo prevent cookie-tossing:
or, if available (applies to earlier JupyterHub versions):
Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 62 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
Fixed in
4.1.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-41942
PYSEC-2024-200
BIT-jupyterhub-2024-41942
GHSA-9x4q-3gxw-849f
Aug 08, 2024
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 68 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
Fixed in
4.1.6
References Updated Jan 19, 2025 · Source: OSV.dev | ||
4.0.0
major
4 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-28233
PYSEC-2026-1480
BIT-jupyterhub-2024-28233
GHSA-7r3h-4ph8-w38g
Jul 07, 2026
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
ImpactAffected configurations:
By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS directly affecting the former's session. More precisely, in the context of JupyterHub, this XSS could achieve the following:
PatchesTo prevent cookie-tossing:
or, if available (applies to earlier JupyterHub versions):
Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 62 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
Fixed in
4.1.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-41942
PYSEC-2024-200
BIT-jupyterhub-2024-41942
GHSA-9x4q-3gxw-849f
Aug 08, 2024
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 68 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
Fixed in
4.1.6
References Updated Jan 19, 2025 · Source: OSV.dev | ||
4.0.0b2
pre
4 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-28233
PYSEC-2026-1480
BIT-jupyterhub-2024-28233
GHSA-7r3h-4ph8-w38g
Jul 07, 2026
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
ImpactAffected configurations:
By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS directly affecting the former's session. More precisely, in the context of JupyterHub, this XSS could achieve the following:
PatchesTo prevent cookie-tossing:
or, if available (applies to earlier JupyterHub versions):
Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 62 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
Fixed in
4.1.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-41942
PYSEC-2024-200
BIT-jupyterhub-2024-41942
GHSA-9x4q-3gxw-849f
Aug 08, 2024
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 68 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
Fixed in
4.1.6
References Updated Jan 19, 2025 · Source: OSV.dev | ||
4.0.0b1
pre
4 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-28233
PYSEC-2026-1480
BIT-jupyterhub-2024-28233
GHSA-7r3h-4ph8-w38g
Jul 07, 2026
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
ImpactAffected configurations:
By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS directly affecting the former's session. More precisely, in the context of JupyterHub, this XSS could achieve the following:
PatchesTo prevent cookie-tossing:
or, if available (applies to earlier JupyterHub versions):
Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 62 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
Fixed in
4.1.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-41942
PYSEC-2024-200
BIT-jupyterhub-2024-41942
GHSA-9x4q-3gxw-849f
Aug 08, 2024
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 68 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
Fixed in
4.1.6
References Updated Jan 19, 2025 · Source: OSV.dev | ||
3.1.1
patch
4 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-28233
PYSEC-2026-1480
BIT-jupyterhub-2024-28233
GHSA-7r3h-4ph8-w38g
Jul 07, 2026
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
ImpactAffected configurations:
By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS directly affecting the former's session. More precisely, in the context of JupyterHub, this XSS could achieve the following:
PatchesTo prevent cookie-tossing:
or, if available (applies to earlier JupyterHub versions):
Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 62 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
Fixed in
4.1.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-41942
PYSEC-2024-200
BIT-jupyterhub-2024-41942
GHSA-9x4q-3gxw-849f
Aug 08, 2024
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 68 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
Fixed in
4.1.6
References Updated Jan 19, 2025 · Source: OSV.dev | ||
3.1.0
minor
4 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-28233
PYSEC-2026-1480
BIT-jupyterhub-2024-28233
GHSA-7r3h-4ph8-w38g
Jul 07, 2026
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
ImpactAffected configurations:
By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS directly affecting the former's session. More precisely, in the context of JupyterHub, this XSS could achieve the following:
PatchesTo prevent cookie-tossing:
or, if available (applies to earlier JupyterHub versions):
Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 62 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
Fixed in
4.1.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-41942
PYSEC-2024-200
BIT-jupyterhub-2024-41942
GHSA-9x4q-3gxw-849f
Aug 08, 2024
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 68 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
Fixed in
4.1.6
References Updated Jan 19, 2025 · Source: OSV.dev | ||
1.5.1
patch
4 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-28233
PYSEC-2026-1480
BIT-jupyterhub-2024-28233
GHSA-7r3h-4ph8-w38g
Jul 07, 2026
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
ImpactAffected configurations:
By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS directly affecting the former's session. More precisely, in the context of JupyterHub, this XSS could achieve the following:
PatchesTo prevent cookie-tossing:
or, if available (applies to earlier JupyterHub versions):
Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 62 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
Fixed in
4.1.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-41942
PYSEC-2024-200
BIT-jupyterhub-2024-41942
GHSA-9x4q-3gxw-849f
Aug 08, 2024
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 68 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
Fixed in
4.1.6
References Updated Jan 19, 2025 · Source: OSV.dev | ||
3.0.0
major
4 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-28233
PYSEC-2026-1480
BIT-jupyterhub-2024-28233
GHSA-7r3h-4ph8-w38g
Jul 07, 2026
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
ImpactAffected configurations:
By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS directly affecting the former's session. More precisely, in the context of JupyterHub, this XSS could achieve the following:
PatchesTo prevent cookie-tossing:
or, if available (applies to earlier JupyterHub versions):
Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 62 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
Fixed in
4.1.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-41942
PYSEC-2024-200
BIT-jupyterhub-2024-41942
GHSA-9x4q-3gxw-849f
Aug 08, 2024
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 68 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
Fixed in
4.1.6
References Updated Jan 19, 2025 · Source: OSV.dev | ||
3.0.0b1
pre
4 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-28233
PYSEC-2026-1480
BIT-jupyterhub-2024-28233
GHSA-7r3h-4ph8-w38g
Jul 07, 2026
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
ImpactAffected configurations:
By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS directly affecting the former's session. More precisely, in the context of JupyterHub, this XSS could achieve the following:
PatchesTo prevent cookie-tossing:
or, if available (applies to earlier JupyterHub versions):
Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 62 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
Fixed in
4.1.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-41942
PYSEC-2024-200
BIT-jupyterhub-2024-41942
GHSA-9x4q-3gxw-849f
Aug 08, 2024
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 68 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
Fixed in
4.1.6
References Updated Jan 19, 2025 · Source: OSV.dev | ||
2.3.1
patch
4 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-28233
PYSEC-2026-1480
BIT-jupyterhub-2024-28233
GHSA-7r3h-4ph8-w38g
Jul 07, 2026
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
ImpactAffected configurations:
By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS directly affecting the former's session. More precisely, in the context of JupyterHub, this XSS could achieve the following:
PatchesTo prevent cookie-tossing:
or, if available (applies to earlier JupyterHub versions):
Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 62 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
Fixed in
4.1.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-41942
PYSEC-2024-200
BIT-jupyterhub-2024-41942
GHSA-9x4q-3gxw-849f
Aug 08, 2024
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 68 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
Fixed in
4.1.6
References Updated Jan 19, 2025 · Source: OSV.dev | ||
2.3.0
minor
4 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-28233
PYSEC-2026-1480
BIT-jupyterhub-2024-28233
GHSA-7r3h-4ph8-w38g
Jul 07, 2026
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
ImpactAffected configurations:
By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS directly affecting the former's session. More precisely, in the context of JupyterHub, this XSS could achieve the following:
PatchesTo prevent cookie-tossing:
or, if available (applies to earlier JupyterHub versions):
Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 62 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
Fixed in
4.1.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-41942
PYSEC-2024-200
BIT-jupyterhub-2024-41942
GHSA-9x4q-3gxw-849f
Aug 08, 2024
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 68 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
Fixed in
4.1.6
References Updated Jan 19, 2025 · Source: OSV.dev | ||
2.2.2
patch
4 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-28233
PYSEC-2026-1480
BIT-jupyterhub-2024-28233
GHSA-7r3h-4ph8-w38g
Jul 07, 2026
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
ImpactAffected configurations:
By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS directly affecting the former's session. More precisely, in the context of JupyterHub, this XSS could achieve the following:
PatchesTo prevent cookie-tossing:
or, if available (applies to earlier JupyterHub versions):
Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 62 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
Fixed in
4.1.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-41942
PYSEC-2024-200
BIT-jupyterhub-2024-41942
GHSA-9x4q-3gxw-849f
Aug 08, 2024
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 68 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
Fixed in
4.1.6
References Updated Jan 19, 2025 · Source: OSV.dev | ||
2.2.1
patch
4 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-28233
PYSEC-2026-1480
BIT-jupyterhub-2024-28233
GHSA-7r3h-4ph8-w38g
Jul 07, 2026
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
ImpactAffected configurations:
By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS directly affecting the former's session. More precisely, in the context of JupyterHub, this XSS could achieve the following:
PatchesTo prevent cookie-tossing:
or, if available (applies to earlier JupyterHub versions):
Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 62 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
Fixed in
4.1.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-41942
PYSEC-2024-200
BIT-jupyterhub-2024-41942
GHSA-9x4q-3gxw-849f
Aug 08, 2024
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 68 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
Fixed in
4.1.6
References Updated Jan 19, 2025 · Source: OSV.dev | ||
2.2.0
minor
4 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-28233
PYSEC-2026-1480
BIT-jupyterhub-2024-28233
GHSA-7r3h-4ph8-w38g
Jul 07, 2026
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
ImpactAffected configurations:
By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS directly affecting the former's session. More precisely, in the context of JupyterHub, this XSS could achieve the following:
PatchesTo prevent cookie-tossing:
or, if available (applies to earlier JupyterHub versions):
Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 62 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
Fixed in
4.1.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-41942
PYSEC-2024-200
BIT-jupyterhub-2024-41942
GHSA-9x4q-3gxw-849f
Aug 08, 2024
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 68 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
Fixed in
4.1.6
References Updated Jan 19, 2025 · Source: OSV.dev | ||
2.1.1
patch
4 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-28233
PYSEC-2026-1480
BIT-jupyterhub-2024-28233
GHSA-7r3h-4ph8-w38g
Jul 07, 2026
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
ImpactAffected configurations:
By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS directly affecting the former's session. More precisely, in the context of JupyterHub, this XSS could achieve the following:
PatchesTo prevent cookie-tossing:
or, if available (applies to earlier JupyterHub versions):
Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 62 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
Fixed in
4.1.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-41942
PYSEC-2024-200
BIT-jupyterhub-2024-41942
GHSA-9x4q-3gxw-849f
Aug 08, 2024
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 68 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
Fixed in
4.1.6
References Updated Jan 19, 2025 · Source: OSV.dev | ||
2.1.0
minor
4 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-28233
PYSEC-2026-1480
BIT-jupyterhub-2024-28233
GHSA-7r3h-4ph8-w38g
Jul 07, 2026
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
ImpactAffected configurations:
By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS directly affecting the former's session. More precisely, in the context of JupyterHub, this XSS could achieve the following:
PatchesTo prevent cookie-tossing:
or, if available (applies to earlier JupyterHub versions):
Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 62 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
Fixed in
4.1.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-41942
PYSEC-2024-200
BIT-jupyterhub-2024-41942
GHSA-9x4q-3gxw-849f
Aug 08, 2024
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 68 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
Fixed in
4.1.6
References Updated Jan 19, 2025 · Source: OSV.dev | ||
2.0.2
patch
4 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-28233
PYSEC-2026-1480
BIT-jupyterhub-2024-28233
GHSA-7r3h-4ph8-w38g
Jul 07, 2026
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
ImpactAffected configurations:
By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS directly affecting the former's session. More precisely, in the context of JupyterHub, this XSS could achieve the following:
PatchesTo prevent cookie-tossing:
or, if available (applies to earlier JupyterHub versions):
Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 62 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
Fixed in
4.1.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-41942
PYSEC-2024-200
BIT-jupyterhub-2024-41942
GHSA-9x4q-3gxw-849f
Aug 08, 2024
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 68 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
Fixed in
4.1.6
References Updated Jan 19, 2025 · Source: OSV.dev | ||
2.0.1
patch
4 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-28233
PYSEC-2026-1480
BIT-jupyterhub-2024-28233
GHSA-7r3h-4ph8-w38g
Jul 07, 2026
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
ImpactAffected configurations:
By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS directly affecting the former's session. More precisely, in the context of JupyterHub, this XSS could achieve the following:
PatchesTo prevent cookie-tossing:
or, if available (applies to earlier JupyterHub versions):
Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 62 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
Fixed in
4.1.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-41942
PYSEC-2024-200
BIT-jupyterhub-2024-41942
GHSA-9x4q-3gxw-849f
Aug 08, 2024
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 68 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
Fixed in
4.1.6
References Updated Jan 19, 2025 · Source: OSV.dev | ||
2.0.0
major
4 CVEs
CVE-2026-54338
PYSEC-2026-3853
GHSA-p43p-whwx-q52h
Sep 10, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactInvalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected. PatchesUpgrade to 5.5.0. WorkaroundsUse an Authenticator that doesn't use a login form, such as OAuthenticator. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 84 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
Fixed in
5.5.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-28233
PYSEC-2026-1480
BIT-jupyterhub-2024-28233
GHSA-7r3h-4ph8-w38g
Jul 07, 2026
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
ImpactAffected configurations:
By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS directly affecting the former's session. More precisely, in the context of JupyterHub, this XSS could achieve the following:
PatchesTo prevent cookie-tossing:
or, if available (applies to earlier JupyterHub versions):
Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 62 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
Fixed in
4.1.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33709
PYSEC-2026-2188
BIT-jupyterhub-2026-33709
GHSA-3vff-hjqv-m7h8
Apr 03, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 81 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
5.0.0
5.0.0b1
5.0.0b2
5.1.0
5.2.0
5.2.1
5.3.0
5.3.0rc0
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
5.4.4
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-41942
PYSEC-2024-200
BIT-jupyterhub-2024-41942
GHSA-9x4q-3gxw-849f
Aug 08, 2024
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.0b1
0.7.1
0.7.2
+ 68 more Show less
0.8.0
0.8.0b1
0.8.0b2
0.8.0b3
0.8.0b4
0.8.0b5
0.8.0rc1
0.8.0rc2
0.8.1
0.9.0
0.9.0b1
0.9.0b2
0.9.0b3
0.9.0rc1
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.0b1
1.2.0
1.2.0b1
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
2.0.0
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.0rc5
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
2.3.1
3.0.0
3.0.0b1
3.1.0
3.1.1
4.0.0
4.0.0b1
4.0.0b2
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
Fixed in
4.1.6
References Updated Jan 19, 2025 · Source: OSV.dev |