CVE-2026-54338: JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
Invalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-54338 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →