CVE-2026-54338
Received Received - Intake

JupyterHub Form Login Authenticator Resource Exhaustion

Vulnerability report for CVE-2026-54338, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-07

Last updated on: 2026-08-07

Assigner: GitHub, Inc.

Description

JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. Prior to 5.5.0, invalid input to form-based login authenticators can place an unbounded attacker-controlled username in failed-login logs, allowing an unauthenticated attacker to consume logging and storage resources. This issue is fixed in version 5.5.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-07
Last Modified
2026-08-07
Generated
2026-08-08
AI Q&A
2026-08-08
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jupyterhub jupyterhub 5.5.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

JupyterHub before version 5.5.0 has a flaw in form-based login where invalid input can insert an attacker-controlled username into failed-login logs. This allows unauthenticated attackers to fill up logging and storage resources by repeatedly triggering failed login attempts.

Detection Guidance

This vulnerability involves logging of attacker-controlled usernames during failed login attempts. Monitor logs for unusually long or malformed usernames in JupyterHub authentication logs. Check for excessive log file growth or storage consumption in JupyterHub directories.

Impact Analysis

An attacker could exploit this to consume excessive disk space and log storage, potentially causing system slowdowns or outages. It may also obscure legitimate login failures in logs due to the flood of fake entries.

Compliance Impact

This vulnerability could indirectly impact compliance with GDPR or HIPAA by enabling resource exhaustion through excessive log storage due to attacker-controlled usernames. Uncontrolled log growth may violate data retention policies or overwhelm storage systems, potentially leading to non-compliance with storage or logging requirements.

Mitigation Strategies

Upgrade JupyterHub to version 5.5.0 or later to address the vulnerability. Monitor failed-login logs for unusually high resource consumption.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54338. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart