Database/AI/ML frameworks & serving
Jupyter Server: login `next` parameter allows redirect to an arbitrary external host
Impact
A crafted login URL for a Jupyter Server instance sends the user to an attacker-controlled site after - or instead of - authenticating. On a GPU fleet the notebook endpoint is usually the one URL researchers are trained to trust and bookmark, so a redirect that keeps the real hostname in the link is a credible way to harvest notebook credentials or tokens, which in turn grant code execution on a GPU node. No data is read and no code runs on the server itself; the whole impact is phishing leverage and it needs the user to click and then act on the destination page. Affects jupyter_server through 2.17.0.
Who can reach it
Anyone who can get a user to open a URL pointing at a reachable Jupyter Server login page. No authentication needed to craft the link; the victim must click it.
What to do
Upgrade jupyter_server to 2.18.0 and restart the notebook service. Cheap where notebooks run as per-user pods or a managed JupyterHub image - rebuild the image and restart sessions; no node drain or reboot. Running sessions are interrupted when the server restarts, so warn users or roll it with their next session.
References
Related entries
- vLLM: video decoder limit bypass via sampler subclass shadowing exhausts unaccounted GPU memoryCVE-2026-100649 · vLLM (PyNvVideoCodec decoder allocation, sampler subclass accounting)Medium
- TrustyAI Service Operator: unauthenticated access to AI guardrail and orchestrator APIsCVE-2026-15044 · TrustyAI Service Operator (Red Hat OpenShift AI)Medium
- llama.cpp: oversized seq_id in a saved slot file leaks heap memory past the cells arrayCVE-2026-43630 · llama.cpp server (recurrent memory state slot-restore path)Medium
- vLLM: race in the prompt_embeds sparse-tensor guard reopens the CVE-2025-62164 crash pathCVE-2026-73557 · vLLM prompt_embeds loader (safe_load_prompt_embeds sparse-tensor guard)Medium
- Eclipse Che dashboard backend (POST /dashboard/api/data/resolver): The dashboard backend passes a user-supplied URLCVE-2026-86590 · Eclipse Che dashboard backend (POST /dashboard/api/data/resolver)Medium
- vLLM: allowed_token_ids validated against tokenizer length, corrupting shared GPU logit-bias stateCVE-2026-93840 · vLLM (SamplingParams allowed_token_ids validation / LogitBiasState)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.