Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.3) | 0.44% | — | JupyterhubAI | 7/8/2026 | 9/9/2026 | JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. Prior to 5.5.0, invalid input to form-based login authenticators can place an unbounded attacker-controlled username in failed-login logs, allowing an unauthenticated attacker to consume logging and storage resources. This… | |
| Analizada | Media (4.3) | 0.18% | 💥 PoC | Jupyterhub | 22/5/2026 | 23/7/2026 | JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF protection (updated in 4.1.0) inappropriately treated requests with Sec-Fetch-Mode: no-cors as same-origin requests, bypassing XSRF checks. The JSON API is not affected, only HTTP form… | |
| Analizada | Media (5.9) | 0.41% | — | LTI Jupyterhub Authenticator | 3/4/2026 | 24/7/2026 | LTI JupyterHub Authenticator is a JupyterHub authenticator for LTI. Prior to version 1.6.3, the LTI 1.1 validator stores OAuth nonces in a class-level dictionary that grows without bounds. Nonces are added before signature validation, so an attacker with knowledge of a valid consumer key can send repeated requests… | |
| Analizada | Media (5.1) | 0.30% | — | Jupyterhub | 3/4/2026 | 24/7/2026 | JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary… | |
| Analizada | Crítica (9.8) | 0.36% | — | LTI Jupyterhub Authenticator | 25/2/2025 | 17/6/2026 | `jupyterhub-ltiauthenticator` is a JupyterHub authenticator for learning tools interoperability (LTI). LTI13Authenticator that was introduced in `jupyterhub-ltiauthenticator` 1.3.0 wasn't validating JWT signatures. This is believed to allow the LTI13Authenticator to authorize a forged request. Only users that has… | |
| Aplazada | Media (6.9) | 0.47% | — | NbgraderAIJupyterhubAI | 17/1/2025 | 17/6/2026 | nbgrader is a system for assigning and grading notebooks. Enabling frame-ancestors: 'self' grants any JupyterHub user the ability to extract formgrader content by sending malicious links to users with access to formgrader, at least when using the default JupyterHub configuration of `enable_subdomains = False`. #1915… | |
| Analizada | Alta (7.2) | 0.59% | — | Jupyterhub | 8/8/2024 | 17/6/2026 | JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the `admin:users` scope, they may escalate their own privileges by making themselves a full admin user. The impact is relatively small in that `admin:users` is already an… | |
| Aplazada | Alta (8.1) | 0.40% | — | JupyterhubAIJupyter OauthenticatorAI | 12/6/2024 | 17/6/2026 | OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. JupyterHub < 5.0, when used with `GlobusOAuthenticator`, could be configured to allow all users from a particular institution only. This worked fine prior to JupyterHub 5.0, because `allow_all` did not take… | |
| Analizada | Media (6.1) | 0.33% | — | Jupyterhub | 27/3/2024 | 17/6/2026 | JupyterHub is an open source multi-user server for Jupyter notebooks. By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS directly affecting the former's session. More precisely, in the context of JupyterHub, this XSS could achieve full access to JupyterHub API and user's… | |
| Modificada | Alta (7.5) | 0.80% | — | Jupyterhub | 4/11/2021 | 17/6/2026 | JupyterHub is an open source multi-user server for Jupyter notebooks. In affected versions users who have multiple JupyterLab tabs open in the same browser session, may see incomplete logout from the single-user server, as fresh credentials (for the single-user server only, not the Hub) reinstated after logout, if… | |
| Modificada | Crítica (9.8) | 1.4% | — | Jupyterhub First USE Authenticator | 28/10/2021 | 17/6/2026 | FirstUseAuthenticator is a JupyterHub authenticator that helps new users set their password on their first login to JupyterHub. When JupyterHub is used with FirstUseAuthenticator, a vulnerability in versions prior to 1.0.0 allows unauthorized access to any user's account if `create_users=True` and the username is… | |
| Modificada | Alta (8.8) | 1.7% | — | Jupyterhub Nbgitpuller | 25/8/2021 | 17/6/2026 | nbgitpuller is a Jupyter server extension to sync a git repository one-way to a local path. Due to unsanitized input, visiting maliciously crafted links could result in arbitrary code execution in the user environment. This has been resolved in version 0.10.2 and all users are advised to upgrade. No work around exist… | |
| Modificada | Media (4.5) | 0.50% | — | Jupyterhub | 13/1/2021 | 17/6/2026 | JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an _xsrf field, as demonstrated by a /hub/api/user request (to add or remove a user account). | |
| Modificada | Alta (7.9) | 0.48% | — | Jupyterhub Systemdspawner | 9/12/2020 | 17/6/2026 | jupyterhub-systemdspawner enables JupyterHub to spawn single-user notebook servers using systemd. In jupyterhub-systemdspawner before version 0.15 user API tokens issued to single-user servers are specified in the environment of systemd units. These tokens are incorrectly accessible to all users. In particular,… | |
| Modificada | Alta (8.1) | 1.1% | — | Jupyterhub Kubespawner | 17/7/2020 | 17/6/2026 | In jupyterhub-kubespawner before 0.12, certain usernames will be able to craft particular server names which will grant them access to the default server of other users who have matching usernames. This has been fixed in 0.12. | |
| Modificada | Media (6.1) | 1.8% | — | JupyterhubJupyter Notebook | 28/3/2019 | 17/6/2026 | An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in JupyterHub before 0.9.5 allows crafted links to the login page, which will redirect to a malicious site after successful login. Servers running on a base_url prefix are not affected. |