{"id":"GHSA-m68r-v472-jgq9","summary":"JupyterHub has cross-origin form POSTs bypass XSRF (CWE-352)","details":"## Summary\n\nJupyterHub's XSRF protection (updated in 4.1.0) inappropriately treated requests with `Sec-Fetch-Mode: no-cors` as same-origin requests, which they are not, bypassing XSRF checks. The JSON API is not affected, only HTTP form endpoints, such as `/hub/spawn` and `/hub/accept-share`, meaning attackers could trigger server spawn (but not access the server) and if the attacker is a JupyterHub user permitted to share access to their server, cause a user to accept a share and have access to the attacker's server.\n\n## Patches\n\nUpgrade to JupyterHub 5.4.5.\n\n## Mitigations\n\nIf a reverse proxy is in use, drop requests to JupyterHub with `Sec-Fetch-Mode: no-cors`.","aliases":["BIT-jupyterhub-2026-40864","CVE-2026-40864","PYSEC-2026-2189"],"modified":"2026-09-10T03:51:06.307577438Z","published":"2026-05-05T18:10:58Z","database_specific":{"nvd_published_at":"2026-05-22T21:16:43Z","cwe_ids":["CWE-352"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-05-05T18:10:58Z"},"references":[{"type":"WEB","url":"https://github.com/jupyterhub/jupyterhub/security/advisories/GHSA-m68r-v472-jgq9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40864"},{"type":"WEB","url":"https://github.com/jupyterhub/jupyterhub/commit/9c5ec277d3cda5a59de2d8c8117efa77bd941127"},{"type":"PACKAGE","url":"https://github.com/jupyterhub/jupyterhub"}],"affected":[{"package":{"name":"jupyterhub","ecosystem":"PyPI","purl":"pkg:pypi/jupyterhub"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.1.0"},{"fixed":"5.4.5"}]}],"versions":["4.1.0","4.1.1","4.1.2","4.1.3","4.1.4","4.1.5","4.1.6","5.0.0","5.0.0b1","5.0.0b2","5.1.0","5.2.0","5.2.1","5.3.0","5.3.0rc0","5.4.0","5.4.1","5.4.2","5.4.3","5.4.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-m68r-v472-jgq9/GHSA-m68r-v472-jgq9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"}]}