PT-2026-30253 · Unknown · Ltiauthenticator+1
Yueyuel
·
Published
2026-04-03
·
Updated
2026-05-18
·
CVE-2026-34052
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
LTI JupyterHub Authenticator versions prior to 1.6.3
Description
The LTI 1.1 validator stores OAuth nonces in a class-level dictionary that grows without bounds. Nonces are added before signature validation, allowing an attacker with a valid consumer key to send repeated requests with unique nonces, gradually exhausting server memory and causing a denial of service.
Recommendations
Upgrade to version 1.6.3 or later.
Fix
Memory Leak
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jupyterhub
Ltiauthenticator