Cross-site Request Forgery (CSRF) Affecting jupyterhub package, versions *


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.16% (6th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIANUNSTABLE-JUPYTERHUB-16894962
  • published27 May 2026
  • disclosed22 May 2026

Introduced: 22 May 2026

CVE-2026-40864  (opens in a new tab)
CWE-352  (opens in a new tab)

How to fix?

There is no fixed version for Debian:unstable jupyterhub.

NVD Description

Note: Versions mentioned in the description apply only to the upstream jupyterhub package and not the jupyterhub package as distributed by Debian. See How to fix? for Debian:unstable relevant fixed versions and status.

JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF protection (updated in 4.1.0) inappropriately treated requests with Sec-Fetch-Mode: no-cors as same-origin requests, bypassing XSRF checks. The JSON API is not affected, only HTTP form endpoints, such as /hub/spawn and /hub/accept-share, meaning attackers could trigger server spawn (but not access the server) and if the attacker is a JupyterHub user permitted to share access to their server, cause a user to accept a share and have access to the attacker's server. This issue has been fixed in version 5.4.5. If developers are unable to immediately upgrade, they can temporarily mitigate this issue by dropping requests to JupyterHub with Sec-Fetch-Mode: no-cors if they are using a reverse proxy.

CVSS Base Scores

version 3.1