MEDIUM 6.1 PyPI

JupyterHub has an Open Redirect Vulnerability

GHSA-3vff-hjqv-m7h8 · BIT-jupyterhub-2026-33709 · CVE-2026-33709 · PYSEC-2026-2188

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Affected Version

JupyterHub <= 5.4.3

Impact

An open redirect vulnerability in JupyterHub <=5.4.3 allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this.

Patches

Upgrade to JupyterHub 5.4.4

Workarounds

A deployment can apply filters on the Location header in a reverse proxy such as nginx/apache/traefik.

Ready to move

Start Securing

Free, no credit card | First findings in minutes