๐Ÿ” CVE Alert

CVE-2026-34052

MEDIUM 5.9

LTI JupyterHub Authenticator: Unbounded Memory Growth via Nonce Storage (Denial of Service)

CVSS Score
5.9
EPSS Score
0.0%
EPSS Percentile
12th

LTI JupyterHub Authenticator is a JupyterHub authenticator for LTI. Prior to version 1.6.3, the LTI 1.1 validator stores OAuth nonces in a class-level dictionary that grows without bounds. Nonces are added before signature validation, so an attacker with knowledge of a valid consumer key can send repeated requests with unique nonces to gradually exhaust server memory, causing a denial of service. This issue has been patched in version 1.6.3.

CWE CWE-401 CWE-770
Vendor jupyterhub
Product ltiauthenticator
Published Apr 3, 2026
Last Updated Apr 6, 2026
Stay Ahead of the Next One

Get instant alerts for jupyterhub ltiauthenticator

Be the first to know when new medium vulnerabilities affecting jupyterhub ltiauthenticator are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

jupyterhub / ltiauthenticator
< 1.6.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/jupyterhub/ltiauthenticator/security/advisories/GHSA-8mxq-7xr7-2fxj github.com: https://github.com/jupyterhub/ltiauthenticator/releases/tag/1.6.3