jupyterhub-ltiauthenticator
JupyterHub authenticator implementing LTI v1.1 and LTI v1.3
Activity
- Latest release
- 5mo ago
- Total releases
- 15
- Cadence
- ~4 months
- Last 12 months
- 1
Reach
- Stars
- —
Details
- License
- custom
- First release
- Dec 16, 2017
| Version | Released | |
|---|---|---|
1.6.3
patch
| ||
1.6.2
patch
1 CVE
CVE-2026-34052
PYSEC-2026-2533
GHSA-8mxq-7xr7-2fxj
Jul 13, 2026
LTI JupyterHub Authenticator: Unbounded Memory Growth via Nonce Storage (Denial of Service)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryThe LTI 1.1 validator stores OAuth nonces in a class-level dictionary that grows without bounds. Nonces are added before signature validation, so an attacker with knowledge of a valid consumer key can send repeated requests with unique nonces to gradually exhaust server memory, causing a denial of service. Patches
Affected versions
0.1
0.2
0.3
0.4.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
+ 2 more Show less
1.6.1
1.6.2
Fixed in
1.6.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.6.1
patch
1 CVE
CVE-2026-34052
PYSEC-2026-2533
GHSA-8mxq-7xr7-2fxj
Jul 13, 2026
LTI JupyterHub Authenticator: Unbounded Memory Growth via Nonce Storage (Denial of Service)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryThe LTI 1.1 validator stores OAuth nonces in a class-level dictionary that grows without bounds. Nonces are added before signature validation, so an attacker with knowledge of a valid consumer key can send repeated requests with unique nonces to gradually exhaust server memory, causing a denial of service. Patches
Affected versions
0.1
0.2
0.3
0.4.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
+ 2 more Show less
1.6.1
1.6.2
Fixed in
1.6.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.6.0
minor
1 CVE
CVE-2026-34052
PYSEC-2026-2533
GHSA-8mxq-7xr7-2fxj
Jul 13, 2026
LTI JupyterHub Authenticator: Unbounded Memory Growth via Nonce Storage (Denial of Service)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryThe LTI 1.1 validator stores OAuth nonces in a class-level dictionary that grows without bounds. Nonces are added before signature validation, so an attacker with knowledge of a valid consumer key can send repeated requests with unique nonces to gradually exhaust server memory, causing a denial of service. Patches
Affected versions
0.1
0.2
0.3
0.4.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
+ 2 more Show less
1.6.1
1.6.2
Fixed in
1.6.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.5.1
patch
1 CVE
CVE-2026-34052
PYSEC-2026-2533
GHSA-8mxq-7xr7-2fxj
Jul 13, 2026
LTI JupyterHub Authenticator: Unbounded Memory Growth via Nonce Storage (Denial of Service)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryThe LTI 1.1 validator stores OAuth nonces in a class-level dictionary that grows without bounds. Nonces are added before signature validation, so an attacker with knowledge of a valid consumer key can send repeated requests with unique nonces to gradually exhaust server memory, causing a denial of service. Patches
Affected versions
0.1
0.2
0.3
0.4.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
+ 2 more Show less
1.6.1
1.6.2
Fixed in
1.6.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.5.0
minor
1 CVE
CVE-2026-34052
PYSEC-2026-2533
GHSA-8mxq-7xr7-2fxj
Jul 13, 2026
LTI JupyterHub Authenticator: Unbounded Memory Growth via Nonce Storage (Denial of Service)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryThe LTI 1.1 validator stores OAuth nonces in a class-level dictionary that grows without bounds. Nonces are added before signature validation, so an attacker with knowledge of a valid consumer key can send repeated requests with unique nonces to gradually exhaust server memory, causing a denial of service. Patches
Affected versions
0.1
0.2
0.3
0.4.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
+ 2 more Show less
1.6.1
1.6.2
Fixed in
1.6.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.4.0
minor
1 CVE
CVE-2026-34052
PYSEC-2026-2533
GHSA-8mxq-7xr7-2fxj
Jul 13, 2026
LTI JupyterHub Authenticator: Unbounded Memory Growth via Nonce Storage (Denial of Service)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryThe LTI 1.1 validator stores OAuth nonces in a class-level dictionary that grows without bounds. Nonces are added before signature validation, so an attacker with knowledge of a valid consumer key can send repeated requests with unique nonces to gradually exhaust server memory, causing a denial of service. Patches
Affected versions
0.1
0.2
0.3
0.4.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
+ 2 more Show less
1.6.1
1.6.2
Fixed in
1.6.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.3.0
minor
2 CVEs
CVE-2026-34052
PYSEC-2026-2533
GHSA-8mxq-7xr7-2fxj
Jul 13, 2026
LTI JupyterHub Authenticator: Unbounded Memory Growth via Nonce Storage (Denial of Service)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryThe LTI 1.1 validator stores OAuth nonces in a class-level dictionary that grows without bounds. Nonces are added before signature validation, so an attacker with knowledge of a valid consumer key can send repeated requests with unique nonces to gradually exhaust server memory, causing a denial of service. Patches
Affected versions
0.1
0.2
0.3
0.4.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
+ 2 more Show less
1.6.1
1.6.2
Fixed in
1.6.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2023-25574
GHSA-mcgx-2gcr-p3hp
PYSEC-2025-120
Feb 25, 2025
LTI JupyterHub Authenticator does not properly validate JWT Signature
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactOnly users that has configured a JupyterHub installation to use the authenticator class LTI13Authenticator that was introduced in PatchesNone. WorkaroundsNone. References
Affected versions
1.3.0
Fixed in
1.4.0
References
Updated Jun 05, 2026 · Source: OSV.dev | ||
1.2.0
minor
1 CVE
CVE-2026-34052
PYSEC-2026-2533
GHSA-8mxq-7xr7-2fxj
Jul 13, 2026
LTI JupyterHub Authenticator: Unbounded Memory Growth via Nonce Storage (Denial of Service)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryThe LTI 1.1 validator stores OAuth nonces in a class-level dictionary that grows without bounds. Nonces are added before signature validation, so an attacker with knowledge of a valid consumer key can send repeated requests with unique nonces to gradually exhaust server memory, causing a denial of service. Patches
Affected versions
0.1
0.2
0.3
0.4.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
+ 2 more Show less
1.6.1
1.6.2
Fixed in
1.6.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.1.0
minor
1 CVE
CVE-2026-34052
PYSEC-2026-2533
GHSA-8mxq-7xr7-2fxj
Jul 13, 2026
LTI JupyterHub Authenticator: Unbounded Memory Growth via Nonce Storage (Denial of Service)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryThe LTI 1.1 validator stores OAuth nonces in a class-level dictionary that grows without bounds. Nonces are added before signature validation, so an attacker with knowledge of a valid consumer key can send repeated requests with unique nonces to gradually exhaust server memory, causing a denial of service. Patches
Affected versions
0.1
0.2
0.3
0.4.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
+ 2 more Show less
1.6.1
1.6.2
Fixed in
1.6.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.0.0
major
1 CVE
CVE-2026-34052
PYSEC-2026-2533
GHSA-8mxq-7xr7-2fxj
Jul 13, 2026
LTI JupyterHub Authenticator: Unbounded Memory Growth via Nonce Storage (Denial of Service)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryThe LTI 1.1 validator stores OAuth nonces in a class-level dictionary that grows without bounds. Nonces are added before signature validation, so an attacker with knowledge of a valid consumer key can send repeated requests with unique nonces to gradually exhaust server memory, causing a denial of service. Patches
Affected versions
0.1
0.2
0.3
0.4.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
+ 2 more Show less
1.6.1
1.6.2
Fixed in
1.6.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.4.0
minor
1 CVE
CVE-2026-34052
PYSEC-2026-2533
GHSA-8mxq-7xr7-2fxj
Jul 13, 2026
LTI JupyterHub Authenticator: Unbounded Memory Growth via Nonce Storage (Denial of Service)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryThe LTI 1.1 validator stores OAuth nonces in a class-level dictionary that grows without bounds. Nonces are added before signature validation, so an attacker with knowledge of a valid consumer key can send repeated requests with unique nonces to gradually exhaust server memory, causing a denial of service. Patches
Affected versions
0.1
0.2
0.3
0.4.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
+ 2 more Show less
1.6.1
1.6.2
Fixed in
1.6.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.3
minor
1 CVE
CVE-2026-34052
PYSEC-2026-2533
GHSA-8mxq-7xr7-2fxj
Jul 13, 2026
LTI JupyterHub Authenticator: Unbounded Memory Growth via Nonce Storage (Denial of Service)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryThe LTI 1.1 validator stores OAuth nonces in a class-level dictionary that grows without bounds. Nonces are added before signature validation, so an attacker with knowledge of a valid consumer key can send repeated requests with unique nonces to gradually exhaust server memory, causing a denial of service. Patches
Affected versions
0.1
0.2
0.3
0.4.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
+ 2 more Show less
1.6.1
1.6.2
Fixed in
1.6.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.2
minor
1 CVE
CVE-2026-34052
PYSEC-2026-2533
GHSA-8mxq-7xr7-2fxj
Jul 13, 2026
LTI JupyterHub Authenticator: Unbounded Memory Growth via Nonce Storage (Denial of Service)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryThe LTI 1.1 validator stores OAuth nonces in a class-level dictionary that grows without bounds. Nonces are added before signature validation, so an attacker with knowledge of a valid consumer key can send repeated requests with unique nonces to gradually exhaust server memory, causing a denial of service. Patches
Affected versions
0.1
0.2
0.3
0.4.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
+ 2 more Show less
1.6.1
1.6.2
Fixed in
1.6.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.1
initial
1 CVE
CVE-2026-34052
PYSEC-2026-2533
GHSA-8mxq-7xr7-2fxj
Jul 13, 2026
LTI JupyterHub Authenticator: Unbounded Memory Growth via Nonce Storage (Denial of Service)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryThe LTI 1.1 validator stores OAuth nonces in a class-level dictionary that grows without bounds. Nonces are added before signature validation, so an attacker with knowledge of a valid consumer key can send repeated requests with unique nonces to gradually exhaust server memory, causing a denial of service. Patches
Affected versions
0.1
0.2
0.3
0.4.0
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
+ 2 more Show less
1.6.1
1.6.2
Fixed in
1.6.3
References
Updated Jul 13, 2026 · Source: OSV.dev |