CVE-2026-40934Disclosure(jupyter / jupyter_server)

LOWCVSS 6.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign authentication cookies is persisted to a static file at ~/.local/share/jupyter/runtime/jupyter_cookie_secret and is never rotated when a user changes their password. After a password reset and server restart, any previously issued authentication cookie remains cryptographically valid because the signing key has not changed. An attacker who has captured a session cookie through any means retains full authenticated access to the server regardless of subsequent password changes. This affects deployments using password-based authentication, particularly shared or public-facing servers where credential rotation is expected to revoke existing sessions. This issue has been fixed in version 2.18.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-613

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jupyter_server

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-05); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
jupyter_server

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-05: 2Mentions · 2026-05-06: 1Technical Details · 2026-05-05: 205-0505-06
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-052
Disclosure2
2026-05-061
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-40934 Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign authentication cookies is persisted to a static fi… https://www.cve.org/CVERecord?id=CVE-2026-40934

    Post summary

    The entry announces CVE‑2026‑40934, highlighting that older Jupyter Server versions store the cookie‑signing secret in a static file, potentially enabling credential compromise.

    00010259
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40934 Authentication Cookie Signing Key Persistence in Jupyter Server 2.17.0 and Earlier https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40934

    Post summary

    The message references CVE-2026-40934 describing an authentication cookie signing key persistence issue in older Jupyter Server versions, but it provides no PoC, exploit code, active exploitation evidence, or mitigation details.

    0000044
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40934 Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign authentication cookies is persisted to a static fi… https://www.cve.org/CVERecord?id=CVE-2026-40934 ----- Traducción: CVE-2026-40934 Jup… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑40934, noting that Jupyter Server keeps the cookie‑signing secret in a static file, but there is no evidence of exploits, patches, or active usage.

    0000033
    75 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjupyterjupyter_server---

Explore more