CVE-2026-108752
JupyterHub through 6.0.1 OAuth Client ID Collision via Unescaped Hyphen
CVSS Score
4.2
EPSS Score
0.0%
EPSS Percentile
0th
JupyterHub through 6.0.1 contains an identifier collision vulnerability that allows authenticated users to overwrite another user's named-server OAuth client by registering a hyphenated username. Attackers holding a name like alice-prod can overwrite the client for alice's server prod, breaking OAuth login and revoking tokens by stopping their own server.
| CWE | CWE-694 |
| Vendor | jupyterhub |
| Product | jupyterhub |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for jupyterhub jupyterhub
Be the first to know when new medium vulnerabilities affecting jupyterhub jupyterhub are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
Low
Affected Versions
jupyterhub / jupyterhub
0 โค 6.0.1
References
hackmd.io: https://hackmd.io/@haind/jupyterhub-oauth-client-id-cross-user-collision github.com: https://github.com/jupyterhub/jupyterhub/blob/3e516c6f382b481e815ec455befb2f14d80d337b/jupyterhub/user.py#L563-L567 github.com: https://github.com/jupyterhub/jupyterhub/blob/3e516c6f382b481e815ec455befb2f14d80d337b/jupyterhub/oauth/provider.py#L719-L754 github.com: https://github.com/jupyterhub/jupyterhub/blob/3e516c6f382b481e815ec455befb2f14d80d337b/jupyterhub/user.py#L1174-L1186 github.com: https://github.com/jupyterhub/jupyterhub vulncheck.com: https://www.vulncheck.com/advisories/jupyterhub-through-6.0.1-oauth-client-id-collision-via-unescaped-hyphen
Credits
HaiND from the Post and Telecommunication Institute of Technology