THREAT OPS › Threat News › [GHSA] GHSA-p43p-whwx-q52h (medium) — JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
[GHSA] GHSA-p43p-whwx-q52h (medium) — JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
GHSA-p43p-whwx-q52h Severity: medium CVE: CVE-2026-54338
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
### Impact
Invalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected.
### Patches
Upgrade to 5.5.0.
### Workarounds
Indicators of compromise
- CVE-2026-54338cve
Original source: https://github.com/advisories/GHSA-p43p-whwx-q52h