Description
@fastify/jwt is a JSON Web Token plugin for the Fastify web framework. In versions before 10.2.3, a time span passed to expiresIn, notBefore, or maxAge that the plugin's parser cannot read, such as a compound span, a month unit, an ISO 8601 duration, a decimal comma, or a value with surrounding whitespace, is silently dropped instead of refused. On the signing path this produces a token with no expiration claim that never expires, and on the verification path a configured maxAge stops being enforced, so a token that should be rejected for age is accepted. The issue is fixed in @fastify/jwt 10.2.3, and users should upgrade to 10.2.3 or later. As a workaround, pass these options as a number of seconds, or verify that any time-span string parses to a finite value before relying on it.
Published: 2026-10-08
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: Authentication/Authorization Bypass
Action: Immediate Upgrade
AI Analysis

Impact

The vulnerability arises when @fastify/jwt parses a temporal option that it cannot interpret, causing the option to be silently discarded. When this occurs on the signing path, the resulting JSON Web Token lacks the required expiration claim and therefore never expires. On the verification side, a configured maxAge is ignored, so tokens older than the intended lifetime are erroneously accepted. This issue provides an attacker with a means to obtain or reuse tokens that should have been considered expired, undermining authentication integrity.

Affected Systems

Affected systems are installations of the @fastify/jwt plugin for the Fastify framework with a version earlier than 10.2.3. The flaw is present in all releases preceding that version and is resolved starting with 10.2.3. Users of the plugin should therefore upgrade to 10.2.3 or a later release to ensure that temporal options are validated and enforced correctly.

Risk and Exploitability

The flaw carries a CVSS score of 6.8 and is not listed in the CISA KEV catalog. No EPSS information is available, so its current exploitability is unknown, but the nature of the bug suggests that any environment allowing an attacker to influence token creation or verification could be used to abuse tokens with indefinite validity. Since the issue occurs during token signing and verification, a compromise of the application’s token handling logic could lead to persistent authorization bypass. The likely attack vector is via the application’s token creation or verification endpoints, which are inferred from the description.

Generated by OpenCVE AI on October 8, 2026 at 12:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade @fastify/jwt to version 10.2.3 or later
  • If upgrading is not immediately possible, ensure that values passed to expiresIn, notBefore, or maxAge are numeric seconds and validate their numeric value before use
  • Verify that any time-span string parses to a finite value before relying on it

Generated by OpenCVE AI on October 8, 2026 at 12:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Description @fastify/jwt is a JSON Web Token plugin for the Fastify web framework. In versions before 10.2.3, a time span passed to expiresIn, notBefore, or maxAge that the plugin's parser cannot read, such as a compound span, a month unit, an ISO 8601 duration, a decimal comma, or a value with surrounding whitespace, is silently dropped instead of refused. On the signing path this produces a token with no expiration claim that never expires, and on the verification path a configured maxAge stops being enforced, so a token that should be rejected for age is accepted. The issue is fixed in @fastify/jwt 10.2.3, and users should upgrade to 10.2.3 or later. As a workaround, pass these options as a number of seconds, or verify that any time-span string parses to a finite value before relying on it.
Title @fastify/jwt vulnerable to missing token expiration when temporal options cannot be parsed
Weaknesses CWE-390
CWE-613
CWE-754
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: openjs

Published:

Updated: 2026-10-08T14:21:22.066Z

Reserved: 2026-10-07T15:36:05.942Z

Link: CVE-2026-107275

cve-icon Vulnrichment

Updated: 2026-10-08T14:21:19.042Z

cve-icon NVD

Status : Received

Published: 2026-10-08T12:17:14.553

Modified: 2026-10-08T15:17:37.343

Link: CVE-2026-107275

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T12:45:18Z

Weaknesses
  • CWE-390

    Detection of Error Condition Without Action

  • CWE-613

    Insufficient Session Expiration

  • CWE-754

    Improper Check for Unusual or Exceptional Conditions