17 Total advisories
17 Vulnerabilities
0 Malware
Dependency scanning
Check whether jupyterhub is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 5.3
CVE-2026-54338
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
MEDIUM 5.3
CVE-2026-54338
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
MEDIUM 5.4
CVE-2026-40864
JupyterHub has cross-origin form POSTs bypass XSRF (CWE-352)
HIGH 7.2
CVE-2024-41942
JupyterHub has a privilege escalation vulnerability with the `admin:users` scope
HIGH 8.1
CVE-2024-28233
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
MEDIUM 6.1
CVE-2019-10255
Open Redirect vulnerability in jupyterhub and notebook
MEDIUM 6.1
CVE-2019-10255
Open Redirect vulnerability in jupyterhub and notebook
MEDIUM 6.1
CVE-2026-33709
CVE-2026-33709
MEDIUM 6.1
CVE-2026-33709
JupyterHub has an Open Redirect Vulnerability
MEDIUM 4.3
CVE-2026-40864
CVE-2026-40864
LOW 3.5
CVE-2021-41247
incomplete JupyterHub logout with simultaneous JupyterLab sessions
HIGH 8.1
CVE-2024-28233
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
HIGH 8.8
PYSEC-2018-151
PYSEC-2018-151
HIGH 7.2
CVE-2024-41942
CVE-2024-41942
MEDIUM 4.5
CVE-2020-36191
Cross-Site Request Forgery in JupyterHub
UNKNOWN
CVE-2021-41247
CVE-2021-41247
UNKNOWN
CVE-2020-36191
CVE-2020-36191
Browse more PyPI advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes