PT-2026-107892 · Fastify · @Fastify/Jwt
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
@fastify/jwt versions prior to 10.2.3
Description
In the @fastify/jwt plugin for the Fastify web framework, the parser fails to handle certain time span formats passed to
expiresIn, notBefore, or maxAge. Unsupported formats include compound spans, month units, ISO 8601 durations, decimal commas, or values with surrounding whitespace. These values are silently dropped rather than refused. During the signing process, this results in tokens without an expiration claim that never expire. During the verification process, the configured maxAge is not enforced, allowing tokens that should be rejected due to age to be accepted.Recommendations
Update to version 10.2.3 or later.
Pass the
expiresIn, notBefore, or maxAge options as a number of seconds.
Verify that any time-span string parses to a finite value before use.Fix
Insufficient Session Expiration
Improper Check for Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
@Fastify/Jwt