Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-54338

Опубликовано: 07 авг. 2026
Источник: debian

Описание

JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. Prior to 5.5.0, invalid input to form-based login authenticators can place an unbounded attacker-controlled username in failed-login logs, allowing an unauthenticated attacker to consume logging and storage resources. This issue is fixed in version 5.5.0.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
jupyterhubunfixedpackage
jupyterhubno-dsatrixiepackage
jupyterhubpostponedbookwormpackage

Примечания

  • https://github.com/jupyterhub/jupyterhub/security/advisories/GHSA-p43p-whwx-q52h

  • Fixed by: https://github.com/jupyterhub/jupyterhub/commit/d6dc595f84b7509969686da31d87d6d69e7fce0a (5.5.0)

Связанные уязвимости

CVSS3: 5.3
ubuntu
29 дней назад

JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. Prior to 5.5.0, invalid input to form-based login authenticators can place an unbounded attacker-controlled username in failed-login logs, allowing an unauthenticated attacker to consume logging and storage resources. This issue is fixed in version 5.5.0.

CVSS3: 5.3
nvd
29 дней назад

JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. Prior to 5.5.0, invalid input to form-based login authenticators can place an unbounded attacker-controlled username in failed-login logs, allowing an unauthenticated attacker to consume logging and storage resources. This issue is fixed in version 5.5.0.

CVSS3: 5.3
github
11 дней назад

JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login