JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. Prior to 5.5.0, invalid input to form-based login authenticators can place an unbounded attacker-controlled username in failed-login logs, allowing an unauthenticated attacker to consume logging and storage resources. This issue is fixed in version 5.5.0.
History

Tue, 11 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Jupyterhub
Jupyterhub jupyterhub
Vendors & Products Jupyterhub
Jupyterhub jupyterhub

Fri, 07 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. Prior to 5.5.0, invalid input to form-based login authenticators can place an unbounded attacker-controlled username in failed-login logs, allowing an unauthenticated attacker to consume logging and storage resources. This issue is fixed in version 5.5.0.
Title JupyterHub: Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2026-08-07T20:52:55.068Z

Updated: 2026-08-11T01:15:53.601Z

Reserved: 2026-06-12T19:23:22.316Z

Link: CVE-2026-54338

cve-icon Vulnrichment

Updated: 2026-08-11T01:15:49.592Z

cve-icon NVD

Status : Received

Published: 2026-08-07T21:17:29.017

Modified: 2026-08-11T02:16:51.603

Link: CVE-2026-54338

cve-icon Redhat

No data.