Insufficient Session Expiration in Jupyter Server - CVE-2026-40934
Published: May 5, 2026
Vulnerability details
The vulnerability allows a remote user to maintain indefinite authenticated access.
The vulnerability exists due to insufficient session expiration in the authentication cookie handling when reusing previously issued authentication cookies after a password reset and server restart. A remote user can reuse a stolen or compromised authentication cookie to maintain indefinite authenticated access.
The issue affects deployments using password authentication.
Affected software
openEuler
python-jupyter-server
python3-jupyter-server
How to mitigate CVE-2026-40934
python-jupyter-server - addressed in versions 2.13.0-3, 2.13.0-4
python3-jupyter-server - addressed in versions 2.13.0-3, 2.13.0-4