PT-2026-30253 · Unknown · Jupyterhub+1
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
LTI JupyterHub Authenticator versions prior to 1.6.3
Description
The LTI 1.1 validator stores OAuth nonces in a class-level dictionary that grows without bounds. Nonces are added before signature validation, allowing an attacker with a valid consumer key to send repeated requests with unique nonces, gradually exhausting server memory and causing a denial of service.
Recommendations
Upgrade to version 1.6.3 or later.
Exploit
Fix
DoS
Allocation of Resources Without Limits
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jupyterhub
Ltiauthenticator