Source: jupyterhub Version: 5.2.1+ds1-4 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for jupyterhub. CVE-2026-40864[0]: | JupyterHub is software that allows users to create a multi-user | server for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF | protection (updated in 4.1.0) inappropriately treated requests with | Sec-Fetch-Mode: no-cors as same-origin requests, bypassing XSRF | checks. The JSON API is not affected, only HTTP form endpoints, such | as /hub/spawn and /hub/accept-share, meaning attackers could trigger | server spawn (but not access the server) and if the attacker is a | JupyterHub user permitted to share access to their server, cause a | user to accept a share and have access to the attacker's server. | This issue has been fixed in version 5.4.5. If developers are unable | to immediately upgrade, they can temporarily mitigate this issue by | dropping requests to JupyterHub with Sec-Fetch-Mode: no-cors if they | are using a reverse proxy. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-40864 https://www.cve.org/CVERecord?id=CVE-2026-40864 [1] https://github.com/jupyterhub/jupyterhub/security/advisories/GHSA-m68r-v472-jgq9 [2] https://github.com/jupyterhub/jupyterhub/commit/9c5ec277d3cda5a59de2d8c8117efa77bd941127 Regards, Salvatore

