MEDIUM 6.1 PyPI
JupyterHub has an Open Redirect Vulnerability
GHSA-3vff-hjqv-m7h8 · BIT-jupyterhub-2026-33709 · CVE-2026-33709
Published · Modified
Description
Affected Version
JupyterHub <= 5.4.3
Impact
An open redirect vulnerability in JupyterHub <=5.4.3 allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this.
Patches
Upgrade to JupyterHub 5.4.4
Workarounds
A deployment can apply filters on the Location header in a reverse proxy such as nginx/apache/traefik.
Ready to move
Start Securing
Free, no credit card | First findings in minutes