GHSA-p43p-whwx-q52hMediumCVSS 5.3

JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login

Published
August 25, 2026
Last Modified
August 25, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

Invalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected.

Patches

Upgrade to 5.5.0.

Workarounds

Use an Authenticator that doesn't use a login form, such as OAuthenticator.

🎯 Affected products1

  • pip/jupyterhub:< 5.5.0

🔗 References (4)