CVE-2026-54338EPSS p20.4%
CVE-2026-54338CVE-2026-54338
Description
JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. Prior to 5.5.0, invalid input to form-based login authenticators can place an unbounded attacker-controlled username in failed-login logs, allowing an unauthenticated attacker to consume logging and storage resources. This issue is fixed in version 5.5.0.
Scoring
| CVSS | 5.3 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
| EPSS | 0.28% probability of exploitation · percentile 20.4% · 2026-08-08T12:02:54Z |
| Last modified | 2026-08-07 |