THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-p43p-whwx-q52h (medium) — JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login

[GHSA] GHSA-p43p-whwx-q52h (medium) — JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login

medgithub_advisoriesPublished 2026-08-25

GHSA-p43p-whwx-q52h Severity: medium CVE: CVE-2026-54338

JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login

### Impact

Invalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected.

### Patches

Upgrade to 5.5.0.

### Workarounds

Indicators of compromise

Original source: https://github.com/advisories/GHSA-p43p-whwx-q52h