PT-2026-30253 · Unknown · Jupyterhub+1

·

CVE-2026-34052

·

Published

2026-04-03

·

Updated

2026-07-24

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions LTI JupyterHub Authenticator versions prior to 1.6.3
Description The LTI 1.1 validator stores OAuth nonces in a class-level dictionary that grows without bounds. Nonces are added before signature validation, allowing an attacker with a valid consumer key to send repeated requests with unique nonces, gradually exhausting server memory and causing a denial of service.
Recommendations Upgrade to version 1.6.3 or later.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-AN27706
CVE-2026-34052
GHSA-8MXQ-7XR7-2FXJ
PYSEC-2026-2533

Affected Products

Jupyterhub
Ltiauthenticator