Junglewise Threat Intelligence

CVE-2026-40934: Jupyter Server insufficient session expiration after password reset

CVE-2026-40934 · Severity: medium · CVSS 6.8 · Published 2026-05-05

Technologies: Jupyter Server, jupyter-server (PyPI). Vendors: Jupyter, PyPI.

Executive brief

Jupyter Server is a backend application used to run interactive web-based notebooks. A security flaw allows previously issued login sessions to remain valid even after a user changes their password or the server is restarted. This means that if an attacker manages to steal a user's session cookie, they can maintain permanent access to the user's data and environment regardless of any security measures taken to reset credentials.

Technical details

Jupyter Server (versions 2.17.0 and earlier) persists the secret used to sign authentication cookies in a static file located at ~/.local/share/jupyter/runtime/jupyter_cookie_secret. This secret is not rotated when a user changes their password or when the server restarts. Consequently, any session cookie signed with this static key remains cryptographically valid. An attacker who has obtained a session cookie (via XSS, local access, or other means) can maintain authenticated access to the server indefinitely, bypassing password-based revocation. The issue is classified as CWE-613 (Insufficient Session Expiration) and is fixed in version 2.18.0.

Affected products

  • Jupyter Jupyter Server <= 2.17.0

Timeline

  • 2026-05-05: advisory: GitHub Advisory GHSA-5mrq-x3x5-8v8f published
  • 2026-05-05: disclosed
  • 2026-05-05: patched: Fixed in version 2.18.0

References

Related threats