YAML Injection Vulnerability in Jupyter Enterprise Gateway Affecting Remote Kernel Launching
CVE-2026-44182

10CRITICAL

Key Information:

Vendor
CVE Published:
16 July 2026

What is CVE-2026-44182?

Jupyter Enterprise Gateway prior to version 3.3.0 is susceptible to a YAML injection vulnerability that allows attackers to manipulate untrusted environment variables, potentially compromising the integrity of Kubernetes manifests. This flaw enables adversaries to inject new fields, overwrite existing critical fields, and introduce document boundaries, posing a risk of creating unauthorized privileged pods. The vulnerability stems from the improper interpolation of environment variables in the Jinja2 template used for manifest rendering, representing a significant security risk in distributed computational environments. This issue has been addressed in version 3.3.0.

Affected Version(s)

enterprise_gateway < 3.3.0

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.