Skip to main content

Vendor/product archive

jupyter / jupyterhub CVEs

Beta · best-effort

7 CVEs tagged to jupyter / jupyterhub0 Critical, 2 High, 4 Medium, 1 Low, 0 Unrated.

CVE-2026-40864

Published May 22, 2026

JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF protection (updated in 4.1.0) inappropriately t…

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-33709

Published Apr 3, 2026

JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers t…

CVSS 5.1 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2024-41942

Published Aug 8, 2024

JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the `admin:users` scope, they m…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-28233

Published Mar 27, 2024

JupyterHub is an open source multi-user server for Jupyter notebooks. By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS directly affecting th…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41247

Published Nov 4, 2021

JupyterHub is an open source multi-user server for Jupyter notebooks. In affected versions users who have multiple JupyterLab tabs open in the same browser session, may see incomp…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-36191

Published Jan 13, 2021

JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an _xsrf field, as demonstrated by a /hub/api/user request (to add or remove a user account).

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10255

Published Mar 28, 2019

An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in JupyterHub before 0.9.5 allows crafted links to the login p…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1