Meet Corgea at Black Hat, BSides Las Vegas & DEF CON
MEDIUM 6.1 PyPI

JupyterHub has an Open Redirect Vulnerability

GHSA-3vff-hjqv-m7h8 · BIT-jupyterhub-2026-33709 · CVE-2026-33709

Published · Modified

Description

Affected Version

JupyterHub <= 5.4.3

Impact

An open redirect vulnerability in JupyterHub <=5.4.3 allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this.

Patches

Upgrade to JupyterHub 5.4.4

Workarounds

A deployment can apply filters on the Location header in a reverse proxy such as nginx/apache/traefik.

Ready to move

Start Securing

Free, no credit card | First findings in minutes