MEDIUM 5.3 PyPI
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
PYSEC-2026-3853 · CVE-2026-54338 · GHSA-p43p-whwx-q52h
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Impact
Invalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected.
Patches
Upgrade to 5.5.0.
Workarounds
Use an Authenticator that doesn't use a login form, such as OAuthenticator.
References
- WEB https://github.com/jupyterhub/jupyterhub/security/advisories/GHSA-p43p-whwx-q52h
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-54338
- WEB https://github.com/jupyterhub/jupyterhub/commit/d6dc595f84b7509969686da31d87d6d69e7fce0a
- PACKAGE https://github.com/jupyterhub/jupyterhub
- PACKAGE https://pypi.org/project/jupyterhub
- ADVISORY https://github.com/advisories/GHSA-p43p-whwx-q52h
Ready to move
Start Securing
Free, no credit card | First findings in minutes