CVE-2026-33709
JupyterHub vulnerability analysis and mitigation

JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4.


SourceNVD

Related JupyterHub vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2021-41247HIGH7.5
  • PythonPython
  • jupyterhub
NoYesNov 04, 2021
CVE-2024-41942HIGH7.2
  • WolfiWolfi
  • py3-jupyterhub
NoYesAug 08, 2024
CVE-2024-28233MEDIUM6.1
  • PythonPython
  • jupyterhub
NoYesMar 27, 2024
CVE-2026-33709MEDIUM5.1
  • JupyterHubJupyterHub
  • cpe:2.3:a:jupyter:jupyterhub
NoYesApr 03, 2026
CVE-2020-36191MEDIUM4.5
  • PythonPython
  • jupyterhub
NoYesJan 13, 2021

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management