Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8mxq-7xr7-2fxj | LTI JupyterHub Authenticator: Unbounded Memory Growth via Nonce Storage (Denial of Service) |
Mon, 13 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jupyter
Jupyter lti Jupyterhub Authenticator |
|
| CPEs | cpe:2.3:a:jupyter:lti_jupyterhub_authenticator:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Jupyter
Jupyter lti Jupyterhub Authenticator |
Tue, 07 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jupyterhub
Jupyterhub ltiauthenticator |
|
| Vendors & Products |
Jupyterhub
Jupyterhub ltiauthenticator |
Mon, 06 Apr 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 03 Apr 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LTI JupyterHub Authenticator is a JupyterHub authenticator for LTI. Prior to version 1.6.3, the LTI 1.1 validator stores OAuth nonces in a class-level dictionary that grows without bounds. Nonces are added before signature validation, so an attacker with knowledge of a valid consumer key can send repeated requests with unique nonces to gradually exhaust server memory, causing a denial of service. This issue has been patched in version 1.6.3. | |
| Title | LTI JupyterHub Authenticator: Unbounded Memory Growth via Nonce Storage (Denial of Service) | |
| Weaknesses | CWE-401 CWE-770 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-06T18:59:04.966Z
Reserved: 2026-03-25T15:29:04.746Z
Link: CVE-2026-34052
Updated: 2026-04-06T18:58:56.743Z
Status : Analyzed
Published: 2026-04-03T23:17:03.777
Modified: 2026-04-13T17:44:00.360
Link: CVE-2026-34052
No data.
OpenCVE Enrichment
Updated: 2026-04-14T16:41:41Z
Github GHSA