Vulnerability Description
JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. Prior to 5.5.0, invalid input to form-based login authenticators can place an unbounded attacker-controlled username in failed-login logs, allowing an unauthenticated attacker to consume logging and storage resources. This issue is fixed in version 5.5.0.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/jupyterhub/jupyterhub/commit/d6dc595f84b7509969686da31d87d6d6
- https://github.com/jupyterhub/jupyterhub/security/advisories/GHSA-p43p-whwx-q52h
FAQ
What is CVE-2026-54338?
CVE-2026-54338 is a vulnerability with a CVSS score of 5.3 (MEDIUM). JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. Prior to 5.5.0, invalid input to form-based login authenticators can place an unbounded attacker-controlle...
How severe is CVE-2026-54338?
CVE-2026-54338 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-54338?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.