Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign authentication cookies is persisted to a static file at ~/.local/share/jupyter/runtime/jupyter_cookie_secret and is never rotated when a user changes their password. After a password reset and server restart, any previously issued authentication cookie remains cryptographically valid because the signing key has not changed. An attacker who has captured a session cookie through any means retains full authenticated access to the server regardless of subsequent password changes. This affects deployments using password-based authentication, particularly shared or public-facing servers where credential rotation is expected to revoke existing sessions. This issue has been fixed in version 2.18.0.
References
| Link | Resource |
|---|---|
| https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-5mrq-x3x5-8v8f | Exploit Vendor Advisory Mitigation |
Configurations
History
11 May 2026, 13:00
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Jupyter
Jupyter jupyter Server |
|
| References | () https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-5mrq-x3x5-8v8f - Exploit, Vendor Advisory, Mitigation | |
| CPE | cpe:2.3:a:jupyter:jupyter_server:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.8 |
07 May 2026, 15:06
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-5mrq-x3x5-8v8f - |
06 May 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-5mrq-x3x5-8v8f - |
05 May 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-05 22:16
Updated : 2026-05-11 13:00
NVD link : CVE-2026-40934
Mitre link : CVE-2026-40934
CVE.ORG link : CVE-2026-40934
JSON object : View
Products Affected
jupyter
- jupyter_server
CWE
CWE-613
Insufficient Session Expiration
