MEDIUM5.9
PYSEC-2026-2533
LTI JupyterHub Authenticator: Unbounded Memory Growth via Nonce Storage (Denial of Service)
Quick fix
PYSEC-2026-2533 — jupyterhub-ltiauthenticator: upgrade to the fixed version with the command below.
pip install --upgrade 'jupyterhub-ltiauthenticator>=1.6.3'Details
## Summary
The LTI 1.1 validator stores OAuth nonces in a class-level dictionary that grows without bounds. Nonces are added before signature validation, so an attacker with knowledge of a valid consumer key can send repeated requests with unique nonces to gradually exhaust server memory, causing a denial of service.
## Patches
- upgrade jupyterhub-litauthenticator to 1.6.3
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/jupyterhub-ltiauthenticator
Introduced in:
0Fixed in: 1.6.3Fix
pip install --upgrade 'jupyterhub-ltiauthenticator>=1.6.3'References
- https://github.com/jupyterhub/ltiauthenticator/security/advisories/GHSA-8mxq-7xr7-2fxj[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-34052[ADVISORY]
- https://github.com/jupyterhub/ltiauthenticator[PACKAGE]
- https://github.com/jupyterhub/ltiauthenticator/releases/tag/1.6.3[WEB]
- https://pypi.org/project/jupyterhub-ltiauthenticator[PACKAGE]
- https://github.com/advisories/GHSA-8mxq-7xr7-2fxj[ADVISORY]