JupyterHub: Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
CVSS Skor
5.3
EPSS İhtimal
%0.4
Risk Skoru
0.0
Yayın
2 ay önce
Etkilenen ürün ve sürüm için yayımlanan güvenlik güncellemesini uygulayın.
Envanterimdeki Etkisi
Yalnızca hesabınıza eklediğiniz kişisel ürünler değerlendirilir; kurumsal envanter burada görünmez.
Oturum kontrol ediliyor…
Zafiyet Açıklaması
DayBreach CVE AI Araştırması
CVE-2026-54338 için toplanan üretici, dağıtım, yama ve güvenlik kaynağı kayıtlarını karşılaştırıp kanıt bağlantılı bir açıklama hazırlayalım.
JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. Prior to 5.5.0, invalid input to form-based login authenticators can place an unbounded attacker-controlled username in failed-login logs, allowing an unauthenticated attacker to consume logging and storage resources. This issue is fixed in version 5.5.0.
IMPACT — Etkilenen Ürünler ve Yazılımlar
RED HAT CSAF/VEX — Ürün Etki Kontrolü
SCORING — CVSS Çoklu Kaynak Skoru
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and display CVSS scores from various sources for each CVE.
| SCORE | VERSION | SEVERITY | VECTOR | SOURCE |
|---|---|---|---|---|
| 5.3 | CVSS 3.x | — | Vektör yayımlanmadı | GitHub Advisory |
| 5.3 | CVSS V3_1 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L | CVE CNA |
| 5.3 | CVSS V31 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L | NVD |
| 0.0 | CVSS 4.0 | — | Vektör yayımlanmadı | GitHub Advisory |
Yama ve İyileştirme Rehberi (Solution)
Solution & Remediation Advisory
1 doğrulanmış yama veya düzeltilmiş sürüm kanıtı bulundu.
5.5.0OSV düzeltilmiş sürüm: 5.5.0
Public exploit ve aktif sömürü durumu
Doğrulanmış exploit istihbaratı
Bu CVE için henüz doğrulanmış public PoC, exploit repository’si veya Metasploit modülü bulunamadı.
Zafiyet Dağılımı ve Saldırı Kalıpları (CWE & CAPEC)
CWE - Common Weakness Enumeration
While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-54338 is associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-54338 weaknesses.
Saldırı Vektörü ve Erişilebilirlik Karakteristiği
Resmi Kaynaklar ve Danışma Bültenleri
CVSS Vektör Radar Grafiği
5.3 / 10Vulnerability Scoring Details
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LYama doğrulandı
Zafiyet Türü (CWE & CAPEC)
İlgili Benzer Açıklar
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
SQL injection in Litellm
netlicensing-mcp: REST Path Traversal Bypasses Token Redaction
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces
Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode
Bu açığı API ile alın
Etkilenen ürünler, sürüm aralıkları, istismar durumu ve yama bilgisi tek istekte; ücretsiz anahtarla.
curl -H "x-api-key: $DAYBREACH_API_KEY" \ "https://api.enginteksut.com.tr/api/v1/intel/cves/CVE-2026-54338"