CVE-2026-54338Medium· 5.3▾ SunlitJupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.3%
Last analysed / modified upstream
Invalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected.
Upgrade to 5.5.0.
Use an Authenticator that doesn't use a login form, such as OAuthenticator.
jupyterhub < 5.5.0Upgrade to a patched release:
jupyterhub 5.5.0Connected by shared product, vendor, weakness, or advisory.
CVE-2024-41942High· 7.2JupyterHub has a privilege escalation vulnerability with the `admin:users` scope
CVE-2026-40864Medium· 5.4JupyterHub has cross-origin form POSTs bypass XSRF (CWE-352)
CVE-2026-33709Medium· 6.1JupyterHub has an Open Redirect Vulnerability
CVE-2021-41247Low· 3.5incomplete JupyterHub logout with simultaneous JupyterLab sessions
CVE-2024-28233High· 8.1Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
CVE-2026-33625High· 8.8LMDeploy is a toolkit for compressing, deploying, and serving large language models