{"api_version":"v1","generated_at":"2026-10-09T23:30:00+00:00","product":{"cve_count":6,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-jupyterhub-jupyterhub-cecf9b69f12f","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/jupyterhub","name":"jupyterhub","next_cursor":null,"observations":[{"affected":"< 5.5.0JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. Prior to 5.5.0, invalid input to form-based login authenticators can place an unbounded attacker-controlled username in failed-login logs, allowing an unauthenticated attacker to consume logging and storage resources. This issue is fixed in version 5.5.0.","affected_versions_present":true,"cve_id":"CVE-2026-54338","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54338","fixed":"5.5.0.","last_modified":"2026-08-11T01:15:53.601Z","patch_url":"https://github.com/jupyterhub/jupyterhub/security/advisories/GHSA-p43p-whwx-q52h","primary_source":"","published":"2026-08-07T20:52:55.068Z"},{"affected":">= 4.1.0, < 5.4.5","affected_versions_present":true,"cve_id":"CVE-2026-40864","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40864","fixed":"5.4.5.","last_modified":"2026-05-26T13:13:51.723Z","patch_url":"https://github.com/jupyterhub/jupyterhub/commit/9c5ec277d3cda5a59de2d8c8117efa77bd941127","primary_source":"","published":"2026-05-22T20:13:05.262Z"},{"affected":"< 5.4.4","affected_versions_present":true,"cve_id":"CVE-2026-33709","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33709","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-06T17:33:47.412Z","patch_url":"https://github.com/jupyterhub/jupyterhub/security/advisories/GHSA-3vff-hjqv-m7h8","primary_source":"","published":"2026-04-03T22:00:46.703Z"},{"affected":"< 4.1.6; >= 5.0.0, < 5.1.0","affected_versions_present":true,"cve_id":"CVE-2024-41942","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-41942","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-08T15:17:06.179Z","patch_url":"https://github.com/jupyterhub/jupyterhub/commit/99e2720b0fc626cbeeca3c6337f917fdacfaa428","primary_source":"","published":"2024-08-08T14:36:44.498Z"},{"affected":"< 4.1.0","affected_versions_present":true,"cve_id":"CVE-2024-28233","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-28233","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-15T14:46:24.624Z","patch_url":"https://github.com/jupyterhub/jupyterhub/commit/e2798a088f5ad45340fe79cdf1386198e664f77f","primary_source":"","published":"2024-03-27T18:16:24.308Z"},{"affected":">= 1.0.0, < 1.5.0 - jupyterhub (pip); < 1.2.0 - jupyterhub (helm)","affected_versions_present":true,"cve_id":"CVE-2021-41247","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-41247","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T03:08:31.580Z","patch_url":"https://github.com/jupyterhub/jupyterhub/commit/5ac9e7f73a6e1020ffddc40321fc53336829fe27","primary_source":"","published":"2021-11-04T17:15:11.000Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"jupyterhub"}}
