CVE-2026-33709: JupyterHub has an Open Redirect Vulnerability
Published Apr 3, 2026
·Updated
## Affected Version JupyterHub <= 5.4.3 ## Impact An open redirect vulnerability in JupyterHub <=5.4.3 allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. ## Patches Upgrade to JupyterHub 5.4.4 ## Workarounds A deployment can apply filters on the Location header in a reverse proxy such as nginx/apache/traefik.
Affected Software
2 affected componentsFixes available
pip/jupyterhub<=5.4.3
5.4.4
jupyter JupyterHub<5.4.4
Event History
Apr 3, 2026
Advisory Published
via GitHub·09:36 PM
Data Sourced
via GitHub·09:36 PM
DescriptionWeaknessAffected Software
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
Affected Software