CVE-2026-44182
Jupyter Enterprise Gateway versions before 3.3.0 allow attackers to inject malicious YAML into Kubernetes manifests by using unescaped environment variables. This flaw can create or modify Kubernetes resources, including privileged pods, through the Jinja2 template. The issue is fixed in version 3.3.0.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Jupyter Enterprise Gateway versions earlier than 3.3.0 running on clusters such as Apache Spark, Kubernetes, or Docker Swarm. Typical users are data scientists and system administrators deploying Jupyter notebooks in distributed environments.
Real-world impact
An attacker who can influence the environment variables can create or modify Kubernetes resources, potentially running privileged containers or escalating privileges within the cluster.
Why this severity
The CVSS score is 10 because the vulnerability allows remote attackers to modify the configuration of critical infrastructure components (Kubernetes pods) with no authentication or user interaction, giving full control over the cluster.
What to do about it
- 01Upgrade Jupyter Enterprise Gateway to version 3.3.0 or later.
- 02Restart the Jupyter Enterprise Gateway service to apply the update.
NVD-referenced vendor advisory
Timeline
- Jul 17, 2026 · 17d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 19, 2026 · 15d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.