Jupyterhub
2 CVEs tracked since 2020. Since Dec 2020, none of them reached CISA KEV.
Jupyterhub CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2020-12 | 2 | 0 |
Products
The products that kept showing up in Jupyterhub's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Jupyterhub.
- CVE-2026-54338JupyterHub: Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login5.3
- CVE-2026-40864JupyterHub: Cross-origin form POSTs bypass XSRF5.4
- CVE-2026-34052LTI JupyterHub Authenticator: Unbounded Memory Growth via Nonce Storage (Denial of Service)5.9
- CVE-2026-33709JupyterHub has an Open Redirect Vulnerability6.1
- CVE-2026-33175OAuthenticator: Authentication Bypass in Auth0OAuthenticator via Unverified Email Claims8.8
- CVE-2025-32428Jupyter Remote Desktop Proxy makes TigerVNC accessible via the network and not just via a UNIX socket as intended9.6
- CVE-2023-25574JupyterHub's LTI13Authenticator: JWT signature not validated10.0
- CVE-2024-41942JupyterHub has a privilege escalation vulnerability with the `admin:users` scope7.2
- CVE-2024-37300Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.08.1
- CVE-2024-35225Jupyter Server Proxy has a reflected XSS issue in host parameter9.6
- CVE-2024-28233XSS in JupyterHub via Self-XSS leveraged by Cookie Tossing8.1
- CVE-2024-29033GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace7.5
- CVE-2024-28179Jupyter Server Proxy's Websocket Proxying does not require authentication9.0
- CVE-2023-48311Any image allowed by default8.0
- CVE-2022-31027Authorization Bypass Through User-Controlled Key when using CILogonOAuthenticator in oauthenticator4.2
The record
- Peak rank
- #198 in Dec 2020
- Busiest month shown
- Dec 2020, 2 CVEs
- Months with a KEV entry
- 0 since Dec 2020
- Monthly snapshots
- 1 since 2020