MEDIUM 5.3 PyPI

JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login

PYSEC-2026-3853 · CVE-2026-54338 · GHSA-p43p-whwx-q52h

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

Invalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected.

Patches

Upgrade to 5.5.0.

Workarounds

Use an Authenticator that doesn't use a login form, such as OAuthenticator.

Ready to move

Start Securing

Free, no credit card | First findings in minutes