{"id":"CVE-2026-33709","aliases":["GHSA-3vff-hjqv-m7h8","BIT-jupyterhub-2026-33709","PYSEC-2026-2188"],"title":"JupyterHub has an Open Redirect Vulnerability","summary":"JupyterHub has an Open Redirect Vulnerability","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","vendor":"jupyterhub","product":"jupyterhub","ecosystem":"pip","affected":["jupyterhub < 5.4.4"],"patched":["jupyterhub 5.4.4"],"published":"2026-04-03","updated":"2026-07-13","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-3vff-hjqv-m7h8","references":[{"url":"https://github.com/jupyterhub/jupyterhub/security/advisories/GHSA-3vff-hjqv-m7h8"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33709"},{"url":"https://github.com/jupyterhub/jupyterhub"},{"url":"https://github.com/jupyterhub/jupyterhub/releases/tag/5.4.4"}],"tags":["osv","pip"],"epss":0.00206,"epssPercentile":0.11033,"ingestedAt":"2026-07-13T18:57:52.106Z","slug":"CVE-2026-33709","body":"## Overview\n\n## Affected Version\n\nJupyterHub <= 5.4.3\n\n## Impact\n\nAn open redirect vulnerability in JupyterHub <=5.4.3 allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this.\n\n## Patches\n\nUpgrade to JupyterHub 5.4.4\n\n## Workarounds\n\nA deployment can apply filters on the Location header in a reverse proxy such as nginx/apache/traefik.\n\n## Affected packages\n\n- `jupyterhub < 5.4.4`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `jupyterhub 5.4.4`","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}