Impact
The vulnerability arises when @fastify/jwt parses a temporal option that it cannot interpret, causing the option to be silently discarded. When this occurs on the signing path, the resulting JSON Web Token lacks the required expiration claim and therefore never expires. On the verification side, a configured maxAge is ignored, so tokens older than the intended lifetime are erroneously accepted. This issue provides an attacker with a means to obtain or reuse tokens that should have been considered expired, undermining authentication integrity.
Affected Systems
Affected systems are installations of the @fastify/jwt plugin for the Fastify framework with a version earlier than 10.2.3. The flaw is present in all releases preceding that version and is resolved starting with 10.2.3. Users of the plugin should therefore upgrade to 10.2.3 or a later release to ensure that temporal options are validated and enforced correctly.
Risk and Exploitability
The flaw carries a CVSS score of 6.8 and is not listed in the CISA KEV catalog. No EPSS information is available, so its current exploitability is unknown, but the nature of the bug suggests that any environment allowing an attacker to influence token creation or verification could be used to abuse tokens with indefinite validity. Since the issue occurs during token signing and verification, a compromise of the application’s token handling logic could lead to persistent authorization bypass. The likely attack vector is via the application’s token creation or verification endpoints, which are inferred from the description.
OpenCVE Enrichment