GHSA-5mrq-x3x5-8v8f · Severity: high · Ecosystem: pip — Jupyter Server's Authentication Cookies Remain Valid After Password Reset and Server Restart
Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign authentication cookies is persisted to a static file at ~/.local/share/jupyter/runtime/jupyter_cookie_secret and is never rotated when a user changes their password. After a password reset and server restart, any previously issued authentication cookie remains cryptographically valid because the signing key has not changed. An attacker who has captured a session cookie through any means retains full authenticated access to the server regardless of subsequent password changes. This affects deployments using password-based authentication, particularly shared or public-facing servers where credential rotation is expected to revoke existing sessions. This issue has been fixed in version 2.18.0.
Conclusion & alert: CVE-2026-40934 is rated Exploit Available (53.5/100): CVSS High severity, with low exploitation likelihood (EPSS 0.31%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.02% | 0.31% | +0.29% |
| 2 | 2026-05-22 | 0.07% | 0.02% | -0.05% |
| 3 | 2026-05-06 | — | 0.07% | — |
Full EPSS history (3 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.6 | 4.0 | HIGH |
|
— | — | [email protected] |
| 6.8 | 3.1 | MEDIUM |
|
1.6 | 5.2 | [email protected] |
GHSA-5mrq-x3x5-8v8f · Severity: high · Ecosystem: pip — Jupyter Server's Authentication Cookies Remain Valid After Password Reset and Server Restart
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2026-40934 not yet assigned priority: Debian including 1 source packages (jupyter-server), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): open 5. | https://security-tracker.debian.org/tracker/CVE-2026-40934 |
ubuntu
|
medium | CVE-2026-40934 medium priority: Ubuntu including 1 source packages (jupyter-server), 5 status rows across 5 suites (jammy, noble, questing, resolute, upstream): needs-triage 5. | https://ubuntu.com/security/CVE-2026-40934 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| jupyter | jupyter_server | < 2.18.0 | cpe:2.3:a:jupyter:jupyter_server:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-5mrq-x3x5-8v8f | Exploit Mitigation Vendor Advisory |