Jupyter Server's Authentication Cookies Remain Valid After Password Reset and Server Restart (CVE-2026-40934) | HOL Guard CVE