oauthenticator
OAuthenticator: Authenticate JupyterHub users with common OAuth providers
Activity
- Latest release
- 5mo ago
- Total releases
- 50
- Cadence
- ~37 days
- Last 12 months
- 1
Reach
- Stars
- —
Details
- License
- BSD-3-Clause
- First release
- Dec 22, 2015
| Version | Released | |
|---|---|---|
17.4.0
minor
| ||
17.3.0
minor
1 CVE
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
17.2.0
minor
1 CVE
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
17.1.0
minor
1 CVE
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
17.0.0
major
1 CVE
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
16.3.1
patch
1 CVE
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
16.3.0
minor
2 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
16.2.1
patch
3 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
16.2.0
minor
3 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
16.1.1
patch
3 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
16.1.0
minor
3 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
16.0.7
patch
3 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
16.0.6
patch
3 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
16.0.5
patch
3 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
16.0.4
patch
3 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
16.0.3
patch
3 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
16.0.2
patch
3 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
16.0.1
patch
3 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
16.0.0
major
3 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
15.1.0
minor
3 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
15.0.1
patch
3 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
15.0.0
major
3 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
14.2.0
minor
4 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-31027
PYSEC-2022-206
GHSA-r7v4-jwx9-wx43
Jun 09, 2022
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of CILogonOAuthenticator is documented to be a list of domains that indicate the institutions whose users are authorized to access this JupyterHub. This authorization is validated by ensuring that the email field provided to us by CILogon has a domain that matches one of the domains listed in Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 16 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
Fixed in
15.0.0
Updated Nov 08, 2023 · Source: OSV.dev | ||
14.1.0
minor
4 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-31027
PYSEC-2022-206
GHSA-r7v4-jwx9-wx43
Jun 09, 2022
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of CILogonOAuthenticator is documented to be a list of domains that indicate the institutions whose users are authorized to access this JupyterHub. This authorization is validated by ensuring that the email field provided to us by CILogon has a domain that matches one of the domains listed in Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 16 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
Fixed in
15.0.0
Updated Nov 08, 2023 · Source: OSV.dev | ||
14.0.0
major
4 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-31027
PYSEC-2022-206
GHSA-r7v4-jwx9-wx43
Jun 09, 2022
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of CILogonOAuthenticator is documented to be a list of domains that indicate the institutions whose users are authorized to access this JupyterHub. This authorization is validated by ensuring that the email field provided to us by CILogon has a domain that matches one of the domains listed in Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 16 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
Fixed in
15.0.0
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.13.0
minor
4 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-31027
PYSEC-2022-206
GHSA-r7v4-jwx9-wx43
Jun 09, 2022
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of CILogonOAuthenticator is documented to be a list of domains that indicate the institutions whose users are authorized to access this JupyterHub. This authorization is validated by ensuring that the email field provided to us by CILogon has a domain that matches one of the domains listed in Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 16 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
Fixed in
15.0.0
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.12.3
patch
4 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-31027
PYSEC-2022-206
GHSA-r7v4-jwx9-wx43
Jun 09, 2022
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of CILogonOAuthenticator is documented to be a list of domains that indicate the institutions whose users are authorized to access this JupyterHub. This authorization is validated by ensuring that the email field provided to us by CILogon has a domain that matches one of the domains listed in Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 16 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
Fixed in
15.0.0
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.12.2
patch
4 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-31027
PYSEC-2022-206
GHSA-r7v4-jwx9-wx43
Jun 09, 2022
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of CILogonOAuthenticator is documented to be a list of domains that indicate the institutions whose users are authorized to access this JupyterHub. This authorization is validated by ensuring that the email field provided to us by CILogon has a domain that matches one of the domains listed in Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 16 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
Fixed in
15.0.0
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.12.1
patch
5 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-31027
PYSEC-2022-206
GHSA-r7v4-jwx9-wx43
Jun 09, 2022
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of CILogonOAuthenticator is documented to be a list of domains that indicate the institutions whose users are authorized to access this JupyterHub. This authorization is validated by ensuring that the email field provided to us by CILogon has a domain that matches one of the domains listed in Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 16 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
Fixed in
15.0.0
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-26250
PYSEC-2020-68
GHSA-384w-5v3f-q499
Dec 01, 2020
OAuthenticator is an OAuth login mechanism for JupyterHub. In oauthenticator from version 0.12.0 and before 0.12.2, the deprecated (in jupyterhub 1.2) configuration Affected versions
0.12.0
0.12.1
Fixed in
0.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.12.0
minor
5 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-31027
PYSEC-2022-206
GHSA-r7v4-jwx9-wx43
Jun 09, 2022
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of CILogonOAuthenticator is documented to be a list of domains that indicate the institutions whose users are authorized to access this JupyterHub. This authorization is validated by ensuring that the email field provided to us by CILogon has a domain that matches one of the domains listed in Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 16 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
Fixed in
15.0.0
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-26250
PYSEC-2020-68
GHSA-384w-5v3f-q499
Dec 01, 2020
OAuthenticator is an OAuth login mechanism for JupyterHub. In oauthenticator from version 0.12.0 and before 0.12.2, the deprecated (in jupyterhub 1.2) configuration Affected versions
0.12.0
0.12.1
Fixed in
0.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.11.0
minor
4 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-31027
PYSEC-2022-206
GHSA-r7v4-jwx9-wx43
Jun 09, 2022
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of CILogonOAuthenticator is documented to be a list of domains that indicate the institutions whose users are authorized to access this JupyterHub. This authorization is validated by ensuring that the email field provided to us by CILogon has a domain that matches one of the domains listed in Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 16 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
Fixed in
15.0.0
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.10.0
minor
4 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-31027
PYSEC-2022-206
GHSA-r7v4-jwx9-wx43
Jun 09, 2022
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of CILogonOAuthenticator is documented to be a list of domains that indicate the institutions whose users are authorized to access this JupyterHub. This authorization is validated by ensuring that the email field provided to us by CILogon has a domain that matches one of the domains listed in Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 16 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
Fixed in
15.0.0
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.9.0
minor
4 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-31027
PYSEC-2022-206
GHSA-r7v4-jwx9-wx43
Jun 09, 2022
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of CILogonOAuthenticator is documented to be a list of domains that indicate the institutions whose users are authorized to access this JupyterHub. This authorization is validated by ensuring that the email field provided to us by CILogon has a domain that matches one of the domains listed in Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 16 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
Fixed in
15.0.0
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.8.2
patch
4 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-31027
PYSEC-2022-206
GHSA-r7v4-jwx9-wx43
Jun 09, 2022
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of CILogonOAuthenticator is documented to be a list of domains that indicate the institutions whose users are authorized to access this JupyterHub. This authorization is validated by ensuring that the email field provided to us by CILogon has a domain that matches one of the domains listed in Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 16 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
Fixed in
15.0.0
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.8.1
patch
4 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-31027
PYSEC-2022-206
GHSA-r7v4-jwx9-wx43
Jun 09, 2022
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of CILogonOAuthenticator is documented to be a list of domains that indicate the institutions whose users are authorized to access this JupyterHub. This authorization is validated by ensuring that the email field provided to us by CILogon has a domain that matches one of the domains listed in Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 16 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
Fixed in
15.0.0
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.8.0
minor
4 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-31027
PYSEC-2022-206
GHSA-r7v4-jwx9-wx43
Jun 09, 2022
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of CILogonOAuthenticator is documented to be a list of domains that indicate the institutions whose users are authorized to access this JupyterHub. This authorization is validated by ensuring that the email field provided to us by CILogon has a domain that matches one of the domains listed in Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 16 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
Fixed in
15.0.0
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.7.3
patch
4 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-31027
PYSEC-2022-206
GHSA-r7v4-jwx9-wx43
Jun 09, 2022
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of CILogonOAuthenticator is documented to be a list of domains that indicate the institutions whose users are authorized to access this JupyterHub. This authorization is validated by ensuring that the email field provided to us by CILogon has a domain that matches one of the domains listed in Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 16 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
Fixed in
15.0.0
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.6.2
patch
4 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-31027
PYSEC-2022-206
GHSA-r7v4-jwx9-wx43
Jun 09, 2022
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of CILogonOAuthenticator is documented to be a list of domains that indicate the institutions whose users are authorized to access this JupyterHub. This authorization is validated by ensuring that the email field provided to us by CILogon has a domain that matches one of the domains listed in Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 16 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
Fixed in
15.0.0
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.7.2
patch
5 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-31027
PYSEC-2022-206
GHSA-r7v4-jwx9-wx43
Jun 09, 2022
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of CILogonOAuthenticator is documented to be a list of domains that indicate the institutions whose users are authorized to access this JupyterHub. This authorization is validated by ensuring that the email field provided to us by CILogon has a domain that matches one of the domains listed in Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 16 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
Fixed in
15.0.0
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-7206
GHSA-8x3m-m3x9-54fj
PYSEC-2018-68
May 13, 2022
JupyterHub OAuthenticator elevation of privilege
High
Network
Low
Low
None
An issue was discovered in Project Jupyter JupyterHub OAuthenticator 0.6.x before 0.6.2 and 0.7.x before 0.7.3. When using JupyterHub with GitLab group whitelisting for access control, group membership was not checked correctly, allowing members not in the whitelisted groups to create accounts on the Hub. (Users were not allowed to access other users' accounts, but could create their own accounts on the Hub linked to their GitLab account. GitLab authentication not using gitlab_group_whitelist is unaffected. No other Authenticators are affected.) Affected versions
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
Fixed in
0.6.2
0.7.3
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
0.7.1
patch
5 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-31027
PYSEC-2022-206
GHSA-r7v4-jwx9-wx43
Jun 09, 2022
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of CILogonOAuthenticator is documented to be a list of domains that indicate the institutions whose users are authorized to access this JupyterHub. This authorization is validated by ensuring that the email field provided to us by CILogon has a domain that matches one of the domains listed in Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 16 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
Fixed in
15.0.0
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-7206
GHSA-8x3m-m3x9-54fj
PYSEC-2018-68
May 13, 2022
JupyterHub OAuthenticator elevation of privilege
High
Network
Low
Low
None
An issue was discovered in Project Jupyter JupyterHub OAuthenticator 0.6.x before 0.6.2 and 0.7.x before 0.7.3. When using JupyterHub with GitLab group whitelisting for access control, group membership was not checked correctly, allowing members not in the whitelisted groups to create accounts on the Hub. (Users were not allowed to access other users' accounts, but could create their own accounts on the Hub linked to their GitLab account. GitLab authentication not using gitlab_group_whitelist is unaffected. No other Authenticators are affected.) Affected versions
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
Fixed in
0.6.2
0.7.3
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
0.7.0
minor
5 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-31027
PYSEC-2022-206
GHSA-r7v4-jwx9-wx43
Jun 09, 2022
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of CILogonOAuthenticator is documented to be a list of domains that indicate the institutions whose users are authorized to access this JupyterHub. This authorization is validated by ensuring that the email field provided to us by CILogon has a domain that matches one of the domains listed in Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 16 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
Fixed in
15.0.0
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-7206
GHSA-8x3m-m3x9-54fj
PYSEC-2018-68
May 13, 2022
JupyterHub OAuthenticator elevation of privilege
High
Network
Low
Low
None
An issue was discovered in Project Jupyter JupyterHub OAuthenticator 0.6.x before 0.6.2 and 0.7.x before 0.7.3. When using JupyterHub with GitLab group whitelisting for access control, group membership was not checked correctly, allowing members not in the whitelisted groups to create accounts on the Hub. (Users were not allowed to access other users' accounts, but could create their own accounts on the Hub linked to their GitLab account. GitLab authentication not using gitlab_group_whitelist is unaffected. No other Authenticators are affected.) Affected versions
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
Fixed in
0.6.2
0.7.3
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
0.6.1
patch
5 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-31027
PYSEC-2022-206
GHSA-r7v4-jwx9-wx43
Jun 09, 2022
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of CILogonOAuthenticator is documented to be a list of domains that indicate the institutions whose users are authorized to access this JupyterHub. This authorization is validated by ensuring that the email field provided to us by CILogon has a domain that matches one of the domains listed in Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 16 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
Fixed in
15.0.0
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-7206
GHSA-8x3m-m3x9-54fj
PYSEC-2018-68
May 13, 2022
JupyterHub OAuthenticator elevation of privilege
High
Network
Low
Low
None
An issue was discovered in Project Jupyter JupyterHub OAuthenticator 0.6.x before 0.6.2 and 0.7.x before 0.7.3. When using JupyterHub with GitLab group whitelisting for access control, group membership was not checked correctly, allowing members not in the whitelisted groups to create accounts on the Hub. (Users were not allowed to access other users' accounts, but could create their own accounts on the Hub linked to their GitLab account. GitLab authentication not using gitlab_group_whitelist is unaffected. No other Authenticators are affected.) Affected versions
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
Fixed in
0.6.2
0.7.3
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
0.6.0
minor
5 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-31027
PYSEC-2022-206
GHSA-r7v4-jwx9-wx43
Jun 09, 2022
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of CILogonOAuthenticator is documented to be a list of domains that indicate the institutions whose users are authorized to access this JupyterHub. This authorization is validated by ensuring that the email field provided to us by CILogon has a domain that matches one of the domains listed in Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 16 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
Fixed in
15.0.0
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-7206
GHSA-8x3m-m3x9-54fj
PYSEC-2018-68
May 13, 2022
JupyterHub OAuthenticator elevation of privilege
High
Network
Low
Low
None
An issue was discovered in Project Jupyter JupyterHub OAuthenticator 0.6.x before 0.6.2 and 0.7.x before 0.7.3. When using JupyterHub with GitLab group whitelisting for access control, group membership was not checked correctly, allowing members not in the whitelisted groups to create accounts on the Hub. (Users were not allowed to access other users' accounts, but could create their own accounts on the Hub linked to their GitLab account. GitLab authentication not using gitlab_group_whitelist is unaffected. No other Authenticators are affected.) Affected versions
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
Fixed in
0.6.2
0.7.3
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
0.5.1
patch
4 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-31027
PYSEC-2022-206
GHSA-r7v4-jwx9-wx43
Jun 09, 2022
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of CILogonOAuthenticator is documented to be a list of domains that indicate the institutions whose users are authorized to access this JupyterHub. This authorization is validated by ensuring that the email field provided to us by CILogon has a domain that matches one of the domains listed in Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 16 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
Fixed in
15.0.0
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.5.0
minor
4 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-31027
PYSEC-2022-206
GHSA-r7v4-jwx9-wx43
Jun 09, 2022
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of CILogonOAuthenticator is documented to be a list of domains that indicate the institutions whose users are authorized to access this JupyterHub. This authorization is validated by ensuring that the email field provided to us by CILogon has a domain that matches one of the domains listed in Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 16 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
Fixed in
15.0.0
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.4.1
patch
4 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-31027
PYSEC-2022-206
GHSA-r7v4-jwx9-wx43
Jun 09, 2022
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of CILogonOAuthenticator is documented to be a list of domains that indicate the institutions whose users are authorized to access this JupyterHub. This authorization is validated by ensuring that the email field provided to us by CILogon has a domain that matches one of the domains listed in Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 16 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
Fixed in
15.0.0
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.4.0
minor
4 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-31027
PYSEC-2022-206
GHSA-r7v4-jwx9-wx43
Jun 09, 2022
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of CILogonOAuthenticator is documented to be a list of domains that indicate the institutions whose users are authorized to access this JupyterHub. This authorization is validated by ensuring that the email field provided to us by CILogon has a domain that matches one of the domains listed in Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 16 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
Fixed in
15.0.0
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.3.0
minor
4 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-31027
PYSEC-2022-206
GHSA-r7v4-jwx9-wx43
Jun 09, 2022
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of CILogonOAuthenticator is documented to be a list of domains that indicate the institutions whose users are authorized to access this JupyterHub. This authorization is validated by ensuring that the email field provided to us by CILogon has a domain that matches one of the domains listed in Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 16 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
Fixed in
15.0.0
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.2.0
minor
4 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-31027
PYSEC-2022-206
GHSA-r7v4-jwx9-wx43
Jun 09, 2022
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of CILogonOAuthenticator is documented to be a list of domains that indicate the institutions whose users are authorized to access this JupyterHub. This authorization is validated by ensuring that the email field provided to us by CILogon has a domain that matches one of the domains listed in Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 16 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
Fixed in
15.0.0
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.1.0
initial
4 CVEs
CVE-2024-37300
PYSEC-2026-1711
GHSA-gprj-3p75-f996
Jul 07, 2026
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactJupyterHub < 5.0, when used with
This worked fine prior to JupyterHub 5.0, because Since JupyterHub 5.0, This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. PatchesOAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. WorkaroundsDo not upgrade to JupyterHub 5.0 when using Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 32 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
Fixed in
16.3.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-29033
PYSEC-2026-1710
GHSA-55m3-44xf-hg4h
Jul 07, 2026
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Summary and impact
The vulnerability is that the actual restriction has been to Google accounts with emails ending with the domain. Such accounts could have been created by anyone which at one time was able to read an email associated with the domain. This was described by Dylan Ayrey (@dxa4481) in this blog post from 15th December 2023. RemediationUpgrade to Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 31 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
Fixed in
16.3.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33175
PYSEC-2026-2238
GHSA-rrvg-cxh4-qhrv
Apr 03, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the usrname_claim, this gives users control over their username and the possibility of account takeover. This issue has been patched in version 17.4.0. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 37 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
15.0.0
15.0.1
15.1.0
16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.0.6
16.0.7
16.1.0
16.1.1
16.2.0
16.2.1
16.3.0
16.3.1
17.0.0
17.1.0
17.2.0
17.3.0
Fixed in
17.4.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2022-31027
PYSEC-2022-206
GHSA-r7v4-jwx9-wx43
Jun 09, 2022
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of CILogonOAuthenticator is documented to be a list of domains that indicate the institutions whose users are authorized to access this JupyterHub. This authorization is validated by ensuring that the email field provided to us by CILogon has a domain that matches one of the domains listed in Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.2.0
0.3.0
0.4.0
0.4.1
+ 16 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
14.0.0
14.1.0
14.2.0
Fixed in
15.0.0
Updated Nov 08, 2023 · Source: OSV.dev |