Skip to content
JupyterGHSA-3vff-hjqv-m7h8

JupyterHub has an Open Redirect Vulnerability

Medium6.1CVE-2026-33709 · Published Apr 3, 2026 · updated Jul 13, 2026

## Affected Version JupyterHub <= 5.4.3 ## Impact An open redirect vulnerability in JupyterHub <=5.4.3 allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. ## Patches Upgrade to JupyterHub 5.4.4 ## Workarounds A deployment can apply filters on the Location header in a reverse proxy such as nginx/apache/traefik.

GitHub advisory

Affected versions

PackageAffectedFixed in
jupyterhub
PyPI
< 5.4.45.4.4
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-601
Also known as
BIT-jupyterhub-2026-33709, CVE-2026-33709, PYSEC-2026-2188

More Jupyter advisories

All Jupyter

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.