CVE-2021-41247Low· 3.5▾ Sunlitincomplete JupyterHub logout with simultaneous JupyterLab sessions
▾ Sunlit zone — Low / medium · no exploitation signal
impact 19.3 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.8%
0.8% → 0.8%
Users of JupyterLab with JupyterHub who have multiple JupyterLab tabs open in the same browser session, may see incomplete logout from the single-user server, as fresh credentials (for the single-user server only, not the Hub) reinstated after logout, if another active JupyterLab session is open while the logout takes place.
Upgrade to JupyterHub 1.5. For distributed deployments, it is jupyterhub in the user environment that needs patching. There are no patches necessary in the Hub environment.
The only workaround is to make sure that only one JupyterLab tab is open when you log out.
jupyterhub >= 1.0.0, < 1.5.0Upgrade to a patched release:
jupyterhub 1.5.0Connected by shared product, vendor, weakness, or advisory.
CVE-2024-41942High· 7.2JupyterHub has a privilege escalation vulnerability with the `admin:users` scope
CVE-2026-54338Medium· 5.3JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
CVE-2026-40864Medium· 5.4JupyterHub has cross-origin form POSTs bypass XSRF (CWE-352)
CVE-2026-33709Medium· 6.1JupyterHub has an Open Redirect Vulnerability
CVE-2024-28233High· 8.1Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing