jupyterhub has 6 CVEs on record between 2021 and 2026. 1 was published in the last 90 days. The median CVSS is 5.8 (medium). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.8
- Publish → KEV
- —
- Last 90 days
- 1 prev 2
Weakness classes
Products
- jupyterhub 6
6
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2024-28233High· 8.1Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing45CVE-2026-40864Medium· 5.4JupyterHub has cross-origin form POSTs bypass XSRF (CWE-352)42CVE-2024-41942High· 7.2JupyterHub has a privilege escalation vulnerability with the `admin:users` scope40CVE-2026-33709Medium· 6.1JupyterHub has an Open Redirect Vulnerability34CVE-2026-54338Medium· 5.3JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login29
jupyterhub vulnerabilities
CVEs affecting jupyterhub, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2026-54338Medium· 5.3JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
▾ Sunlitjupyterhub · jupyterhubEPSS 0.44%via OSV
CVE-2026-40864Medium· 5.4PoCJupyterHub has cross-origin form POSTs bypass XSRF (CWE-352)
JupyterHub has cross-origin form POSTs bypass XSRF (CWE-352)
▾ Twilightjupyterhub · jupyterhubEPSS 0.18%via OSV
CVE-2026-33709Medium· 6.1JupyterHub has an Open Redirect Vulnerability
JupyterHub has an Open Redirect Vulnerability
▾ Sunlitjupyterhub · jupyterhubEPSS 0.30%via OSV
CVE-2024-41942High· 7.2JupyterHub has a privilege escalation vulnerability with the `admin:users` scope
JupyterHub has a privilege escalation vulnerability with the `admin:users` scope
▾ Twilightjupyterhub · jupyterhubEPSS 0.59%via OSV
CVE-2024-28233High· 8.1Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
▾ Twilightjupyterhub · jupyterhubEPSS 0.33%via OSV
CVE-2021-41247Low· 3.5incomplete JupyterHub logout with simultaneous JupyterLab sessions
incomplete JupyterHub logout with simultaneous JupyterLab sessions
▾ Sunlitjupyterhub · jupyterhubEPSS 0.80%via OSV