PT-2026-30253 · Unknown · Ltiauthenticator+1

Yueyuel

·

Published

2026-04-03

·

Updated

2026-05-18

·

CVE-2026-34052

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions LTI JupyterHub Authenticator versions prior to 1.6.3
Description The LTI 1.1 validator stores OAuth nonces in a class-level dictionary that grows without bounds. Nonces are added before signature validation, allowing an attacker with a valid consumer key to send repeated requests with unique nonces, gradually exhausting server memory and causing a denial of service.
Recommendations Upgrade to version 1.6.3 or later.

Fix

Memory Leak

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-AN27706
CVE-2026-34052
GHSA-8MXQ-7XR7-2FXJ

Affected Products

Jupyterhub
Ltiauthenticator