PT-2026-108248 · Npm · Fast-Jwt
CVE-2026-107719
·
Published
2026-10-08
·
Updated
2026-10-09
CVSS v3.1
4.2
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
fast-jwt versions prior to 6.3.4
Description
An expiration-check bypass exists when caching is enabled. The
createVerifier cache may continue accepting a signed JSON Web Token (JWT) after its expiration time if the token contains an exp (expiration) claim but lacks an iat (issued at) claim. This occurs because the cacheSet() function in src/verifier.js only derives the cache deadline from the exp claim when iat is present; otherwise, it falls back to the default cacheTTL (Time To Live). Consequently, a subsequent cache hit returns the saved payload before the verifyToken() function can re-validate the expiration. An attacker possessing a valid bearer token can replay it to extend access until the cache entry expires. This issue does not allow for token forgery.Recommendations
Update fast-jwt to version 6.3.4 or later.
As a temporary workaround, disable the
cache option in the createVerifier configuration to ensure every token is validated against its expiration time.Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fast-Jwt