What is CVE-2026-54338?
A vulnerability in JupyterHub form-based login allows unauthenticated attackers to flood logs with arbitrarily large usernames from failed login attempts, exhausting storage resources. This issue is fixed in version 5.5.0.
Azərbaycanca: JupyterHub proqramında autentifikasiya loqlarına nəzarətsiz məlumat yazılması zəifliyi aşkarlanıb. Bu boşluq autentifikasiya olunmamış hücumçuya uğursuz giriş cəhdləri zamanı log və disk resurslarını dolduraraq xidmətə mane olmağa imkan verir. JupyterHub-u 5.5.0 versiyasına və ya daha yenisinə yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ1
What type of resource exhaustion can the CVE-2026-54338 vulnerability in JupyterHub cause?
This vulnerability can cause exhaustion of log and disk storage resources by allowing uncontrolled data to be written to authentication logs during failed login attempts.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.