---
id: CVE-2026-40934
aliases:
  - GHSA-5mrq-x3x5-8v8f
  - PYSEC-2026-69
title: >-
  Jupyter Server's Authentication Cookies Remain Valid After Password Reset and
  Server Restart
summary: >-
  Jupyter Server's Authentication Cookies Remain Valid After Password Reset and
  Server Restart
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'
vendor: jupyter-server
product: jupyter-server
ecosystem: pip
affected:
  - jupyter-server < 2.18.0
patched:
  - jupyter-server 2.18.0
published: '2026-05-05'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:50:45.692059585Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-5mrq-x3x5-8v8f'
references:
  - url: >-
      https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-5mrq-x3x5-8v8f
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-40934'
  - url: 'https://github.com/jupyter-server/jupyter_server'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/jupyter-server/PYSEC-2026-69.yaml
tags:
  - osv
  - pip
epss: 0.00308
epssPercentile: 0.23841
ingestedAt: '2026-09-12T03:13:01.661Z'
---

## Overview

## Summary

A persistent cookie secret vulnerability allows authenticated users to maintain indefinite access even after password changes. 

The cookie secret used to sign authentication cookies is stored in a permanent file (`~/.local/share/jupyter/runtime/jupyter_cookie_secret`) that is never automatically rotated or cleared, allowing stolen or compromised cookies to remain valid indefinitely regardless of password resets.

## PoC

- Start a Jupyter server with password authentication: `jupyter server password`, `jupyter server`
- Log in with the password and capture the authentication cookie (e.g., just login with a browser).
- Change the password to revoke access: `jupyter server password`
- Restart the server
- Use the old stolen cookie => remains valid and provides full authenticated access.

## Impact

- All jupyter-server deployments using password authentication where security incidents may occur
- Multi-user systems where one user's compromised session should be revocable by administrators
- Shared or public-facing Jupyter servers where credential rotation is a security requirement
- Any deployment where password changes are expected to revoke existing sessions

## Patches

Jupyter Server 2.18+

## Workaround

```bash
rm ~/.local/share/jupyter/runtime/jupyter_cookie_secret
# Then restart the server
```

## Affected packages

- `jupyter-server < 2.18.0`

## Remediation

Upgrade to a patched release:

- `jupyter-server 2.18.0`
