CVE-2026-33709

JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jupyter:jupyterhub:*:*:*:*:*:*:*:*

History

22 Apr 2026, 15:59

Type Values Removed Values Added
First Time Jupyter jupyterhub
Jupyter
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CPE cpe:2.3:a:jupyter:jupyterhub:*:*:*:*:*:*:*:*
References () https://github.com/jupyterhub/jupyterhub/releases/tag/5.4.4 - () https://github.com/jupyterhub/jupyterhub/releases/tag/5.4.4 - Product
References () https://github.com/jupyterhub/jupyterhub/security/advisories/GHSA-3vff-hjqv-m7h8 - () https://github.com/jupyterhub/jupyterhub/security/advisories/GHSA-3vff-hjqv-m7h8 - Mitigation, Vendor Advisory

03 Apr 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-03 22:16

Updated : 2026-04-22 15:59


NVD link : CVE-2026-33709

Mitre link : CVE-2026-33709

CVE.ORG link : CVE-2026-33709


JSON object : View

Products Affected

jupyter

  • jupyterhub
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')