Source: jupyterhub
Version: 5.2.1+ds1-4
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for jupyterhub.

CVE-2026-40864[0]:
| JupyterHub is software that allows users to create a multi-user
| server for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF
| protection (updated in 4.1.0) inappropriately treated requests with
| Sec-Fetch-Mode: no-cors as same-origin requests, bypassing XSRF
| checks. The JSON API is not affected, only HTTP form endpoints, such
| as /hub/spawn and /hub/accept-share, meaning attackers could trigger
| server spawn (but not access the server) and if the attacker is a
| JupyterHub user permitted to share access to their server, cause a
| user to accept a share and have access to the attacker's server.
| This issue has been fixed in version 5.4.5. If developers are unable
| to immediately upgrade, they can temporarily mitigate this issue by
| dropping requests to JupyterHub with Sec-Fetch-Mode: no-cors if they
| are using a reverse proxy.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-40864
    https://www.cve.org/CVERecord?id=CVE-2026-40864
[1] 
https://github.com/jupyterhub/jupyterhub/security/advisories/GHSA-m68r-v472-jgq9
[2] 
https://github.com/jupyterhub/jupyterhub/commit/9c5ec277d3cda5a59de2d8c8117efa77bd941127

Regards,
Salvatore

Reply via email to