Sceawere
Vulnerability Detail
CVE-2026-108752UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
JupyterHub OAuth Client Identifier Collision
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.2
- Creation Date
- 4h ago
- Vendor
- jupyterhub
- Product
- jupyterhub
- Attack Type
- Use of Multiple Resources with Duplicate Identifier
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
- Attack Complexity
- HIGH
Narrative and Response
Description
JupyterHub through 6.0.1 contains an identifier collision vulnerability that allows authenticated users to overwrite another user's named-server OAuth client by registering a hyphenated username. Attackers holding a name like alice-prod can overwrite the client for alice's server prod, breaking OAuth login and revoking tokens by stopping their own server.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.2",
"pubDate": "2026-10-11T13:17:20.097Z",
"pubdate": "2026-10-11T13:17:20.097Z",
"executiveSummary": "JupyterHub versions through 6.0.1 are susceptible to an identifier collision vulnerability that facilitates the unauthorized overwriting of OAuth clients associated with named servers.\nThe vulnerability stems from improper handling of username strings during the registration process, specifically regarding hyphenated identifiers.\nAn authenticated attacker can register a username that overlaps with the namespace of an existing user's named server (e.g., registering 'alice-prod' to collide with user 'alice' server 'prod').\nThis collision allows the attacker to hijack or overwrite the OAuth client configuration corresponding to the victim's server.\nImpact includes the total disruption of OAuth authentication flows for the victim, potential credential invalidation, and the ability for the attacker to revoke access tokens by manipulating the state of the compromised client.\nThis flaw represents a significant security risk in multi-tenant environments, as it allows for cross-user interference and denial-of-service against authenticated sessions.",
"technicalDetails": "The root cause of this vulnerability is an ambiguity in the mapping logic used by JupyterHub to associate OAuth clients with specific user-server pairs. The system fails to strictly enforce namespace isolation between primary user accounts and named-server identifiers when creating OAuth client entries.\nJupyterHub utilizes a concatenation or similar derivation method to generate unique identifiers for OAuth clients associated with named servers. When a user creates a named server, an OAuth client is registered in the backing store. The vulnerability arises because the naming scheme does not properly sanitize or distinguish between a legitimate username and a crafted, hyphenated string that mimics the 'user-server' naming convention.\nThe exploitation process follows a logical sequence: First, the attacker identifies a target user (e.g., 'alice') and a specific named server associated with that user (e.g., 'prod'). Second, the attacker registers a new account on the same JupyterHub instance using the username 'alice-prod'. Third, upon the registration of this account, the underlying OAuth client registration logic detects the collision but, due to improper input validation and lack of collision prevention, erroneously overwrites or binds the OAuth client configuration for the existing 'alice/prod' server to the attacker's newly created 'alice-prod' identity.\nOnce the collision is successful, the attacker gains the ability to manipulate the OAuth client parameters. Because the client is now effectively controlled or corrupted by the attacker's account, they can disrupt the OAuth handshake process for the victim. By intentionally stopping their own server, the attacker can force the revocation or invalidation of tokens associated with the hijacked OAuth client, effectively performing a denial-of-service attack on the victim's ability to access their named server.\nThis vulnerability is restricted to authenticated users, meaning an attacker must possess the ability to create an account on the target JupyterHub instance. No administrative privileges are required, but the attacker must possess knowledge of the target's username and the existence of specific named servers to effectively target a user.\nThe vulnerability affects all JupyterHub versions up to and including 6.0.1. The flaw exists within the core server-spawning and OAuth registration logic, making it a critical concern for any deployment utilizing named servers for multi-user session management."
}