PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108752 jupyterhub CVE debrief

JupyterHub through 6.0.1 contains an identifier collision vulnerability allowing authenticated users to overwrite another user's named-server OAuth client by registering a hyphenated username. This vulnerability can be exploited by users registering usernames with hyphens, potentially leading to unauthorized access and disruption of OAuth login functionality. Defenders should assess exposure and verify OAuth client configurations to mitigate potential impacts. The vulnerability highlights the importance of monitoring user registration activity and ensuring secure configuration of OAuth clients.

Vendor
jupyterhub
Product
Unknown
CVSS
LOW 2.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-11
Original CVE updated
2026-10-11
Advisory published
2026-10-11
Advisory updated
2026-10-11

Who should care

Defenders responsible for JupyterHub deployments should assess exposure and verify OAuth client configurations. Security teams and vulnerability management teams should also be aware of this vulnerability and its potential impacts on the organization. Additionally, operators and administrators of JupyterHub instances should be aware of the potential for disruption of OAuth login functionality and take steps to mitigate this risk.

Why it matters

Defenders should care about CVE-2026-108752 because it allows authenticated users to overwrite OAuth clients, potentially disrupting login functionality and requiring verification of configurations.

  • Potential disruption of OAuth login functionality
  • Possible revocation of tokens due to client overwriting
  • Need for verification of OAuth client configurations
  • Importance of monitoring user registration activity

Technical summary

The vulnerability allows authenticated users to overwrite another user's named-server OAuth client by registering a hyphenated username, potentially breaking OAuth login and revoking tokens. This can occur when a user registers a username with a hyphen, which can be confused with another user's named-server OAuth client. The vulnerability highlights the need for secure configuration and monitoring of OAuth clients to prevent unauthorized access and disruption of login functionality. Defenders should prioritize verifying OAuth client configurations and monitoring for suspicious user registration activity.

Defensive priority

Defenders should prioritize verifying OAuth client configurations and monitoring for suspicious user registration activity.

Recommended defensive actions

  • Verify OAuth client configurations for potential collisions
  • Monitor user registration activity for suspicious patterns
  • Review and update JupyterHub to the latest version if possible
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • technicalSummary

Evidence notes

The CVE record and source item provide details on the vulnerability, but additional information on affected versions and remediation is limited. Further verification is needed to determine the full scope of affected systems and to confirm the efficacy of proposed mitigations. Defenders should consult official advisories and track updates from the vendor for comprehensive guidance.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108752 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108752

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108752 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108752

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • JupyterHub through 6.0.1 OAuth Client ID Collision via Unescaped Hyphen

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108752.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://hackmd.io/@haind/jupyterhub-oauth-client-id-cross-user-collision

    Supplemental source - third-party-advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/jupyterhub/jupyterhub/blob/3e516c6f382b481e815ec455befb2f14d80d337b/jupyterhub/user.py

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/jupyterhub/jupyterhub/blob/3e516c6f382b481e815ec455befb2f14d80d337b/jupyterhub/oauth/provider.py

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/jupyterhub/jupyterhub

    Supplemental source - product

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/jupyterhub-through-6.0.1-oauth-client-id-collision-via-unescaped-hyphen

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.