<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T20:32:37.540230+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2020-15110</id>
    <title>CVE-2020-15110 — Possible pod name collisions in jupyterhub-kubespawner</title>
    <updated>2026-10-10T20:32:37.574067+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> jupyterhub kubespawner</p>
<p>In jupyterhub-kubespawner before 0.12, certain usernames will be able to craft particular server names which will grant them access to the default server of other users who have matching usernames. This has been fixed in 0.12.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2020-15110"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-v7m9-9497-p9gr</id>
    <title>GHSA-v7m9-9497-p9gr — Possible pod name collisions in jupyterhub-kubespawner</title>
    <updated>2026-10-10T20:32:37.574129+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: jupyterhub-kubespawner</p>
<p>### Impact
_What kind of vulnerability is it? Who is impacted?_</p>
<p>JupyterHub deployments using:</p>
<p>- KubeSpawner &lt;= 0.11.1 (e.g. zero-to-jupyterhub 0.9.0) and
- enabled named_servers (not default), and
- an Authenticator that allows:
  - usernames with hyphens or other characters that require escape (e.g. `user-hyphen` or `user@email`), and
  - usernames which may match other usernames up to but not including the escaped character (e.g. `user` in the above cases)</p>
<p>In this circumstance, certain usernames will be able to craft particular server names which will grant them access to the default server of other users who have matching usernames.</p>
<p>### Patches
_Has the problem been patched? What versions should users upgrade to?_</p>
<p>Patch will be released in kubespawner 0.12 and zero-to-jupyterhub 0.9.1</p>
<p>### Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_</p>
<p>#### KubeSpawner</p>
<p>Specify configuration:</p>
<p>for KubeSpawner
```python
from traitlets import default
from kubespawner import KubeSpawner</p>
<p>class PatchedKubeSpawner(KubeSpawner):
    @default("pod_name_template")
    def _default_pod_name_template(self):
        if self.name:
            return "jupyter-{username}-{servername}"
        else:
            return "jupyter-{username}"</p>
<p>@default("pvc_name_template")
    def _default_pvc_name_template(self):
        if self.name:
            return "claim-{username}-{servername}"
        else:
            return "claim-{username}"</p>
<p>c.JupyterHu…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-v7m9-9497-p9gr"/>
  </entry>
</feed>
