PatchSiren cyber security CVE debrief
CVE-2026-108752 jupyterhub CVE debrief
JupyterHub through 6.0.1 contains an identifier collision vulnerability allowing authenticated users to overwrite another user's named-server OAuth client by registering a hyphenated username. This vulnerability can be exploited by users registering usernames with hyphens, potentially leading to unauthorized access and disruption of OAuth login functionality. Defenders should assess exposure and verify OAuth client configurations to mitigate potential impacts. The vulnerability highlights the importance of monitoring user registration activity and ensuring secure configuration of OAuth clients.
- Vendor
- jupyterhub
- Product
- Unknown
- CVSS
- LOW 2.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-11
- Original CVE updated
- 2026-10-11
- Advisory published
- 2026-10-11
- Advisory updated
- 2026-10-11
Who should care
Defenders responsible for JupyterHub deployments should assess exposure and verify OAuth client configurations. Security teams and vulnerability management teams should also be aware of this vulnerability and its potential impacts on the organization. Additionally, operators and administrators of JupyterHub instances should be aware of the potential for disruption of OAuth login functionality and take steps to mitigate this risk.
Why it matters
Defenders should care about CVE-2026-108752 because it allows authenticated users to overwrite OAuth clients, potentially disrupting login functionality and requiring verification of configurations.
- Potential disruption of OAuth login functionality
- Possible revocation of tokens due to client overwriting
- Need for verification of OAuth client configurations
- Importance of monitoring user registration activity
Technical summary
The vulnerability allows authenticated users to overwrite another user's named-server OAuth client by registering a hyphenated username, potentially breaking OAuth login and revoking tokens. This can occur when a user registers a username with a hyphen, which can be confused with another user's named-server OAuth client. The vulnerability highlights the need for secure configuration and monitoring of OAuth clients to prevent unauthorized access and disruption of login functionality. Defenders should prioritize verifying OAuth client configurations and monitoring for suspicious user registration activity.
Defensive priority
Defenders should prioritize verifying OAuth client configurations and monitoring for suspicious user registration activity.
Recommended defensive actions
- Verify OAuth client configurations for potential collisions
- Monitor user registration activity for suspicious patterns
- Review and update JupyterHub to the latest version if possible
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- technicalSummary
Evidence notes
The CVE record and source item provide details on the vulnerability, but additional information on affected versions and remediation is limited. Further verification is needed to determine the full scope of affected systems and to confirm the efficacy of proposed mitigations. Defenders should consult official advisories and track updates from the vendor for comprehensive guidance.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108752 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108752
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108752 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108752
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
JupyterHub through 6.0.1 OAuth Client ID Collision via Unescaped Hyphen
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108752.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://hackmd.io/@haind/jupyterhub-oauth-client-id-cross-user-collision
Supplemental source - third-party-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/jupyterhub/jupyterhub/blob/3e516c6f382b481e815ec455befb2f14d80d337b/jupyterhub/user.py
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/jupyterhub/jupyterhub/blob/3e516c6f382b481e815ec455befb2f14d80d337b/jupyterhub/oauth/provider.py
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/jupyterhub/jupyterhub
Supplemental source - product
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/jupyterhub-through-6.0.1-oauth-client-id-collision-via-unescaped-hyphen
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.