Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p43p-whwx-q52h

Опубликовано: 25 авг. 2026
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login

Impact

Invalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected.

Patches

Upgrade to 5.5.0.

Workarounds

Use an Authenticator that doesn't use a login form, such as OAuthenticator.

Пакеты

Наименование

jupyterhub

pip
Затронутые версииВерсия исправления

< 5.5.0

5.5.0

EPSS

Процентиль: 21%
0.00282
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 5.3
ubuntu
29 дней назад

JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. Prior to 5.5.0, invalid input to form-based login authenticators can place an unbounded attacker-controlled username in failed-login logs, allowing an unauthenticated attacker to consume logging and storage resources. This issue is fixed in version 5.5.0.

CVSS3: 5.3
nvd
29 дней назад

JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. Prior to 5.5.0, invalid input to form-based login authenticators can place an unbounded attacker-controlled username in failed-login logs, allowing an unauthenticated attacker to consume logging and storage resources. This issue is fixed in version 5.5.0.

CVSS3: 5.3
debian
29 дней назад

JupyterHub is software that allows users to create a multi-user server ...

EPSS

Процентиль: 21%
0.00282
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-400