← Back

CVE-2026-34052

nvd nist
Published: Apr 3, 2026Modified: Jul 24, 2026

JSON object

Loading...
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.2 / Impact: 3.6
Source: security-advisories@github.com (Secondary)

Description

LTI JupyterHub Authenticator is a JupyterHub authenticator for LTI. Prior to version 1.6.3, the LTI 1.1 validator stores OAuth nonces in a class-level dictionary that grows without bounds. Nonces are added before signature validation, so an attacker with knowledge of a valid consumer key can send repeated requests with unique nonces to gradually exhaust server memory, causing a denial of service. This issue has been patched in version 1.6.3.

Affected (1)

1 product
Lti Jupyterhub Authenticator
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.6.3

References (2)

Timeline

No history available yet.