YAML Injection Vulnerability in Jupyter Enterprise Gateway Affecting Remote Kernel Launching
CVE-2026-44182
10CRITICAL
What is CVE-2026-44182?
Jupyter Enterprise Gateway prior to version 3.3.0 is susceptible to a YAML injection vulnerability that allows attackers to manipulate untrusted environment variables, potentially compromising the integrity of Kubernetes manifests. This flaw enables adversaries to inject new fields, overwrite existing critical fields, and introduce document boundaries, posing a risk of creating unauthorized privileged pods. The vulnerability stems from the improper interpolation of environment variables in the Jinja2 template used for manifest rendering, representing a significant security risk in distributed computational environments. This issue has been addressed in version 3.3.0.
Affected Version(s)
enterprise_gateway < 3.3.0
