SCA: security update for jupyter_enterprise_gateway (GHSA-chq7-94j8-cj28)

critical Tenable Self-Hosted Container Security Plugin ID 442599

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like
Apache Spark, Kubernetes, and Docker Swarm. Versions 2.0.0rc1 and above prior to 3.3.0 have a prohibited
UID and GID feature that by default prevents launching kernels with UID or GID 0 (root), and this
restriction can be bypassed using a specially crafted KERNEL_UID or KERNEL_GID value. This input
validation vulnerability allows running Jupyter kernels as root, which can be dangerous as it allows more
attack surface, and may lead to container escapes, compromising the worker node and all workloads running
on it. Repeated exploitation can compromise all worker nodes, and thus the entire Kubernetes cluster. It
is possible to specify volume mounts, so one vector for a container escape is to use a hostPath R/W volume
mount, use this UID/GID bypass to run as root, and then gain code execution in the underlying worker node
by creating a crontab entry in the mounted host file system. This issue has been fixed in version 3.0.0.
(CVE-2026-44180)

Solution

Update the jupyter_enterprise_gateway library and its related packages to version 3.3.0 or later.

See Also

https://github.com/advisories/GHSA-chq7-94j8-cj28

Plugin Details

Severity: Critical

ID: 442599

Version: Revision 1.5

Type: Local

Family: SCA Checks

Published: 6/4/2026

Updated: 7/20/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: High

Score: 7.9

Percentile: 99.35

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-44180

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 6/3/2026

Vulnerability Publication Date: 6/3/2026

Reference Information

CVE: CVE-2026-44180