CVE-2026-108752
Received Received - Intake

JupyterHub OAuth Client Identifier Collision Vulnerability

Vulnerability report for CVE-2026-108752, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

JupyterHub through 6.0.1 contains an identifier collision vulnerability that allows authenticated users to overwrite another user's named-server OAuth client by registering a hyphenated username. Attackers holding a name like alice-prod can overwrite the client for alice's server prod, breaking OAuth login and revoking tokens by stopping their own server.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jupyterhub jupyterhub 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-694 The product uses multiple resources that can have the same identifier, in a context in which unique identifiers are required.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-108752 is an OAuth client ID collision vulnerability in JupyterHub versions up to 6.0.1. It occurs when a user with a hyphenated username (e.g., alice-prod) can overwrite the OAuth client of another user's named server (e.g., alice's prod server). This happens because both generate the same OAuth client identifier (jupyterhub-user-alice-prod), allowing the attacker to disrupt OAuth login, revoke tokens, and stop the targeted server.

Detection Guidance

To detect this vulnerability, check JupyterHub logs for OAuth client collisions or unexpected server stops. Look for users with hyphenated names (e.g., alice-prod) and verify if their named servers conflict with other users' servers. Inspect the OAuth client identifiers in the database for duplicate entries.

Impact Analysis

If exploited, this vulnerability allows an authenticated attacker to disrupt another user's JupyterHub server by overwriting its OAuth client. This can cause login failures, token revocation, and server shutdowns for affected users. The attack requires named servers to be enabled and an authenticator allowing hyphenated usernames.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling unauthorized access or privilege escalation within JupyterHub environments. If exploited, it may lead to unauthorized data access, token revocation, or session disruption, which could violate data protection requirements under these regulations.

Mitigation Strategies

Upgrade JupyterHub to a version beyond 6.0.1. Disable named servers if not required. Restrict usernames to avoid hyphens. Review and revoke any compromised OAuth tokens. Monitor logs for suspicious activity related to OAuth client collisions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108752. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart