Input Validation Flaw in Jupyter Notebook Kernels on Jupyter Enterprise Gateway
CVE-2026-44180

9.8CRITICAL

Key Information:

Vendor
CVE Published:
16 July 2026

What is CVE-2026-44180?

The Jupyter Enterprise Gateway, which operates Jupyter Notebook kernels across distributed environments such as Apache Spark and Kubernetes, has an input validation vulnerability affecting versions 2.0.0rc1 to prior to 3.3.0. The vulnerability allows attackers to bypass restrictions that prevent kernel execution as root by manipulating KERNEL_UID or KERNEL_GID values. This flaw increases the attack surface significantly, enabling potential container escapes and compromising host nodes. Attackers can exploit this issue to execute code on host systems through malicious volume mounts, which can escalate threats across the Kubernetes cluster. The vulnerability has been addressed in version 3.0.0.

Affected Version(s)

enterprise_gateway >= 2.0.0rc1, < 3.3.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.