CVE-2026-34052Medium· 5.9▾ SunlitLTI JupyterHub Authenticator: Unbounded Memory Growth via Nonce Storage (Denial of Service)
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.3%
Last analysed / modified upstream
The LTI 1.1 validator stores OAuth nonces in a class-level dictionary that grows without bounds. Nonces are added before signature validation, so an attacker with knowledge of a valid consumer key can send repeated requests with unique nonces to gradually exhaust server memory, causing a denial of service.
jupyterhub-ltiauthenticator < 1.6.3Upgrade to a patched release:
jupyterhub-ltiauthenticator 1.6.3