Insufficient Session Expiration in Jupyter Server - CVE-2026-40934
Published: May 5, 2026
Jupyter Server
Jupyter
Description
The vulnerability allows a remote user to maintain indefinite authenticated access.
The vulnerability exists due to insufficient session expiration in the authentication cookie handling when reusing previously issued authentication cookies after a password reset and server restart. A remote user can reuse a stolen or compromised authentication cookie to maintain indefinite authenticated access.
The issue affects deployments using password authentication.