<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 20:32:37 +0000</lastBuildDate>
    <item>
      <title>CVE-2020-15110 — Possible pod name collisions in jupyterhub-kubespawner</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2020-15110</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; jupyterhub kubespawner&lt;/p&gt;
&lt;p&gt;In jupyterhub-kubespawner before 0.12, certain usernames will be able to craft particular server names which will grant them access to the default server of other users who have matching usernames. This has been fixed in 0.12.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; jupyterhub kubespawner&lt;/p&gt;
&lt;p&gt;In jupyterhub-kubespawner before 0.12, certain usernames will be able to craft particular server names which will grant them access to the default server of other users who have matching usernames. This has been fixed in 0.12.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2020-15110</guid>
    </item>
    <item>
      <title>GHSA-v7m9-9497-p9gr — Possible pod name collisions in jupyterhub-kubespawner</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v7m9-9497-p9gr</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: jupyterhub-kubespawner&lt;/p&gt;
&lt;p&gt;### Impact
_What kind of vulnerability is it? Who is impacted?_&lt;/p&gt;
&lt;p&gt;JupyterHub deployments using:&lt;/p&gt;
&lt;p&gt;- KubeSpawner &amp;lt;= 0.11.1 (e.g. zero-to-jupyterhub 0.9.0) and
- enabled named_servers (not default), and
- an Authenticator that allows:
  - usernames with hyphens or other characters that require escape (e.g. `user-hyphen` or `user@email`), and
  - usernames which may match other usernames up to but not including the escaped character (e.g. `user` in the above cases)&lt;/p&gt;
&lt;p&gt;In this circumstance, certain usernames will be able to craft particular server names which will grant them access to the default server of other users who have matching usernames.&lt;/p&gt;
&lt;p&gt;### Patches
_Has the problem been patched? What versions should users upgrade to?_&lt;/p&gt;
&lt;p&gt;Patch will be released in kubespawner 0.12 and zero-to-jupyterhub 0.9.1&lt;/p&gt;
&lt;p&gt;### Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_&lt;/p&gt;
&lt;p&gt;#### KubeSpawner&lt;/p&gt;
&lt;p&gt;Specify configuration:&lt;/p&gt;
&lt;p&gt;for KubeSpawner
```python
from traitlets import default
from kubespawner import KubeSpawner&lt;/p&gt;
&lt;p&gt;class PatchedKubeSpawner(KubeSpawner):
    @default(&amp;#34;pod_name_template&amp;#34;)
    def _default_pod_name_template(self):
        if self.name:
            return &amp;#34;jupyter-{username}-{servername}&amp;#34;
        else:
            return &amp;#34;jupyter-{username}&amp;#34;&lt;/p&gt;
&lt;p&gt;@default(&amp;#34;pvc_name_template&amp;#34;)
    def _default_pvc_name_template(self):
        if self.name:
            return &amp;#34;claim-{username}-{servername}&amp;#34;
        else:
            return &amp;#34;claim-{username}&amp;#34;&lt;/p&gt;
&lt;p&gt;c.JupyterHu…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: jupyterhub-kubespawner&lt;/p&gt;
&lt;p&gt;### Impact
_What kind of vulnerability is it? Who is impacted?_&lt;/p&gt;
&lt;p&gt;JupyterHub deployments using:&lt;/p&gt;
&lt;p&gt;- KubeSpawner &amp;lt;= 0.11.1 (e.g. zero-to-jupyterhub 0.9.0) and
- enabled named_servers (not default), and
- an Authenticator that allows:
  - usernames with hyphens or other characters that require escape (e.g. `user-hyphen` or `user@email`), and
  - usernames which may match other usernames up to but not including the escaped character (e.g. `user` in the above cases)&lt;/p&gt;
&lt;p&gt;In this circumstance, certain usernames will be able to craft particular server names which will grant them access to the default server of other users who have matching usernames.&lt;/p&gt;
&lt;p&gt;### Patches
_Has the problem been patched? What versions should users upgrade to?_&lt;/p&gt;
&lt;p&gt;Patch will be released in kubespawner 0.12 and zero-to-jupyterhub 0.9.1&lt;/p&gt;
&lt;p&gt;### Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_&lt;/p&gt;
&lt;p&gt;#### KubeSpawner&lt;/p&gt;
&lt;p&gt;Specify configuration:&lt;/p&gt;
&lt;p&gt;for KubeSpawner
```python
from traitlets import default
from kubespawner import KubeSpawner&lt;/p&gt;
&lt;p&gt;class PatchedKubeSpawner(KubeSpawner):
    @default(&amp;#34;pod_name_template&amp;#34;)
    def _default_pod_name_template(self):
        if self.name:
            return &amp;#34;jupyter-{username}-{servername}&amp;#34;
        else:
            return &amp;#34;jupyter-{username}&amp;#34;&lt;/p&gt;
&lt;p&gt;@default(&amp;#34;pvc_name_template&amp;#34;)
    def _default_pvc_name_template(self):
        if self.name:
            return &amp;#34;claim-{username}-{servername}&amp;#34;
        else:
            return &amp;#34;claim-{username}&amp;#34;&lt;/p&gt;
&lt;p&gt;c.JupyterHu…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v7m9-9497-p9gr</guid>
    </item>
  </channel>
</rss>
