PT-2026-107892 · Fastify · @Fastify/Jwt

·

CVE-2026-107275

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions @fastify/jwt versions prior to 10.2.3
Description In the @fastify/jwt plugin for the Fastify web framework, the parser fails to handle certain time span formats passed to expiresIn, notBefore, or maxAge. Unsupported formats include compound spans, month units, ISO 8601 durations, decimal commas, or values with surrounding whitespace. These values are silently dropped rather than refused. During the signing process, this results in tokens without an expiration claim that never expire. During the verification process, the configured maxAge is not enforced, allowing tokens that should be rejected due to age to be accepted.
Recommendations Update to version 10.2.3 or later. Pass the expiresIn, notBefore, or maxAge options as a number of seconds. Verify that any time-span string parses to a finite value before use.

Fix

Insufficient Session Expiration

Improper Check for Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107275

Affected Products

@Fastify/Jwt