Junglewise Threat Intelligence

CVE-2026-33175: JupyterHub OAuthenticator authentication bypass in Auth0OAuthenticator

CVE-2026-33175 · Severity: high · CVSS 8.8 · Published 2026-04-03

Technologies: oauthenticator (PyPI). Vendors: PyPI.

Executive brief

JupyterHub OAuthenticator, a tool used to manage user logins via external identity providers, contains a security flaw when used with Auth0. An attacker can use an unverified email address to impersonate a legitimate user, potentially gaining full access to that user's account and data. This could lead to unauthorized access to sensitive research environments or corporate data stored within JupyterHub.

Technical details

An authentication bypass vulnerability exists in the Auth0OAuthenticator component of JupyterHub's OAuthenticator library. The root cause is the failure to validate the 'email_verified' claim from Auth0 identity tokens. When the 'username_claim' is configured to use the email address, an attacker can register an account on the Auth0 tenant with a victim's email address; even if unverified, OAuthenticator accepts the identity, leading to account takeover. This requires the attacker to have basic registration privileges on the same Auth0 tenant used by the JupyterHub instance. The issue is resolved in version 17.4.0 by enforcing the 'email_verified' check.

Affected products

  • JupyterHub oauthenticator < 17.4.0

Timeline

  • 2026-03-26: patched: Version 17.4.0 released
  • 2026-04-02: advisory: GitHub Security Advisory published
  • 2026-04-03: disclosed: CVE-2026-33175 published to NVD

References

Related threats