CVE-2026-34052: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-34052 is a denial-of-service vulnerability in the LTI JupyterHub Authenticator (jupyterhub-ltiauthenticator) caused by unbounded memory growth in the LTI 1.1 OAuth nonce storage mechanism. It affects all versions up to and including 1.6.2, with version 1.6.3 containing the fix. The vulnerability was published on April 3, 2026, with the advisory originally authored by maintainer minrk on April 2, 2026. It carries a CVSS v3.1 base score of 5.9 (Medium) (Github Advisory, JupyterHub Advisory).

Technical details

The root cause is a class-level Python dictionary used to store OAuth nonces in the LTI 1.1 validator that is never bounded or purged, classified under CWE-401 (Missing Release of Memory after Effective Lifetime) and CWE-770 (Allocation of Resources Without Limits or Throttling). Critically, nonces are inserted into this dictionary before OAuth signature validation is performed, meaning an attacker does not need a valid signature — only a known valid consumer key — to add entries. By sending a high volume of requests with unique nonces, an attacker can continuously grow the in-memory dictionary until the server exhausts available memory and becomes unavailable (Github Advisory, JupyterHub Advisory).

Impact

Successful exploitation results in a denial of service through server memory exhaustion, causing the JupyterHub instance to become unresponsive or crash. There is no impact on confidentiality or data integrity — the attack is purely an availability concern. Educational and research environments relying on LTI 1.1-based authentication for JupyterHub access would be most affected, potentially disrupting learning management system (LMS) integrations and user access (Github Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.019% (6th percentile), indicating a low near-term exploitation probability. The attack requires knowledge of a valid LTI consumer key, which raises the effective complexity slightly, though no authentication or user interaction is otherwise needed (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Reconnaissance: Identify a JupyterHub instance using LTI 1.1 authentication (e.g., via LMS integration endpoints such as /lti/launch). Confirm the target is running jupyterhub-ltiauthenticator version 1.6.2 or earlier.
  2. Obtain a valid consumer key: Acquire a legitimate LTI consumer key, which may be available through institutional LMS configurations, documentation, or social engineering. The consumer key is required to pass the initial pre-validation check.
  3. Craft repeated LTI launch requests: Construct valid-looking LTI 1.1 OAuth-signed POST requests to the LTI launch endpoint, each containing a unique oauth_nonce value. The signature does not need to be valid — only the consumer key must be recognized.
  4. Flood the endpoint: Send a large volume of these requests in rapid succession (e.g., using curl in a loop, Python requests, or a custom script), each with a freshly generated unique nonce.
  5. Exhaust server memory: Each request causes a new nonce entry to be added to the unbounded class-level dictionary. Over time, the growing dictionary consumes all available server memory, causing the JupyterHub process to slow down, become unresponsive, or crash, resulting in a denial of service (Github Advisory, JupyterHub Advisory).

Indicators of compromise

  • Network: High volume of POST requests to the LTI launch endpoint (e.g., /lti/launch) from one or more source IPs, each with a unique oauth_nonce parameter in the request body.
  • Logs: JupyterHub access logs showing a rapid succession of LTI launch requests with the same oauth_consumer_key but differing oauth_nonce values; HTTP 500 errors or timeout responses following a period of high request volume.
  • Process/System: Steadily increasing memory consumption by the JupyterHub Python process (jupyterhub or python) observable via system monitoring tools (e.g., top, htop, Prometheus metrics); OOM (Out of Memory) killer events in system logs (/var/log/syslog or dmesg) referencing the JupyterHub process.
  • Application: JupyterHub becoming unresponsive or returning gateway errors; LTI authentication failures for legitimate users following the attack.

Mitigation and workarounds

The primary remediation is to upgrade jupyterhub-ltiauthenticator to version 1.6.3, which addresses the unbounded nonce storage issue. This can be done via pip install --upgrade jupyterhub-ltiauthenticator. As interim workarounds, administrators should implement rate limiting on the LTI launch endpoint at the reverse proxy or web application firewall level, and enable memory usage monitoring with alerting for the JupyterHub process. Stricter validation or allowlisting of consumer keys at the network perimeter can also reduce exposure (JupyterHub Advisory, Release 1.6.3).

Community reactions

The vulnerability was reported by researcher yueyueL and the advisory was published by JupyterHub maintainer minrk. Red Hat has acknowledged the CVE in their security tracking (Red Hat CVE). No significant broader media coverage or notable community debate has been observed, consistent with the moderate severity rating and lack of active exploitation.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management