PT-2026-108248 · Npm · Fast-Jwt

CVE-2026-107719

·

Published

2026-10-08

·

Updated

2026-10-09

CVSS v3.1

4.2

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions fast-jwt versions prior to 6.3.4
Description An expiration-check bypass exists when caching is enabled. The createVerifier cache may continue accepting a signed JSON Web Token (JWT) after its expiration time if the token contains an exp (expiration) claim but lacks an iat (issued at) claim. This occurs because the cacheSet() function in src/verifier.js only derives the cache deadline from the exp claim when iat is present; otherwise, it falls back to the default cacheTTL (Time To Live). Consequently, a subsequent cache hit returns the saved payload before the verifyToken() function can re-validate the expiration. An attacker possessing a valid bearer token can replay it to extend access until the cache entry expires. This issue does not allow for token forgery.
Recommendations Update fast-jwt to version 6.3.4 or later. As a temporary workaround, disable the cache option in the createVerifier configuration to ensure every token is validated against its expiration time.

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107719
GHSA-X937-HJ6V-793P

Affected Products

Fast-Jwt