CVE-2026-108752
Received
Received - Intake
JupyterHub OAuth Client Identifier Collision Vulnerability
Vulnerability report for CVE-2026-108752, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-11
Last updated on: 2026-10-11
Assigner: VulnCheck
Description
Description
JupyterHub through 6.0.1 contains an identifier collision vulnerability that allows authenticated users to overwrite another user's named-server OAuth client by registering a hyphenated username. Attackers holding a name like alice-prod can overwrite the client for alice's server prod, breaking OAuth login and revoking tokens by stopping their own server.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| jupyterhub | jupyterhub | 0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-694 | The product uses multiple resources that can have the same identifier, in a context in which unique identifiers are required. |