Source: jupyterhub Version: 5.2.1+ds1-5 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for jupyterhub. CVE-2026-54338[0]: | JupyterHub is software that allows users to create a multi-user | server for Jupyter notebooks. Prior to 5.5.0, invalid input to form- | based login authenticators can place an unbounded attacker- | controlled username in failed-login logs, allowing an | unauthenticated attacker to consume logging and storage resources. | This issue is fixed in version 5.5.0. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-54338 https://www.cve.org/CVERecord?id=CVE-2026-54338 [1] https://github.com/jupyterhub/jupyterhub/security/advisories/GHSA-p43p-whwx-q52h [2] https://github.com/jupyterhub/jupyterhub/commit/d6dc595f84b7509969686da31d87d6d69e7fce0a Please adjust the affected versions in the BTS as needed. Regards, Salvatore

