Description
fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.4, the fast-jwt createVerifier cache can continue accepting a previously valid, signed JWT after its exp time when caching is enabled and the token has exp but no iat. In src/verifier.js, cacheSet derives the exp cache deadline only when iat is present, so the cache falls back to cacheTTL, and a later cache hit returns the saved payload before verifyToken rechecks expiration. An attacker who can replay the same cached bearer token can extend access until the cache entry expires, but cannot forge a token through this issue. This issue is fixed in version 6.3.4.
Published: 2026-10-08
Score: 4.2 Medium
EPSS: n/a
KEV: No
Impact: Expired token replay via cache
Action: Patch
AI Analysis

Impact

This vulnerability affects the fast-jwt library, where the verifier cache does not enforce expiration for tokens lacking an iat claim. When caching is enabled, an attacker who replays a previously valid, but now expired, bearer token can obtain access until the cached entry expires. Although the attacker cannot forge a token, the ability to extend the life of an existing token permits continued unauthorized access for the cache duration.

Affected Systems

Vendors using the fast-jwt library released by nearform are impacted. Any installation utilizing pre‑6.3.4 versions of fast‑jwt is vulnerable. The issue was resolved in release 6.3.4.

Risk and Exploitability

This vulnerability has a CVSS of 4.2, indicating moderate risk. The EPSS score is not available, so overall exploit probability cannot be quantified. Since it is not listed in the CISA KEV catalog, there are no current known large‑scale exploitation campaigns documented. An attacker who can inject a cached bearer token into an HTTP request is able to bypass expiration, assuming network visibility to the application. Mitigation directly involves updating to a patched version or disabling the verifier cache.

Generated by OpenCVE AI on October 8, 2026 at 23:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade fast-jwt to version 6.3.4 or newer.
  • If upgrading is not immediately possible, disable the verifier cache or ensure tokens include an iat claim to prevent cache expiration bypass.
  • Audit the dependency tree to confirm no older fast-jwt versions remain in use and monitor authentication logs for repeated token replays.

Generated by OpenCVE AI on October 8, 2026 at 23:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-x937-hj6v-793p fast-jwt: Verifier cache accepts expired JWTs without iat.
History

Thu, 08 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
Description fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.4, the fast-jwt createVerifier cache can continue accepting a previously valid, signed JWT after its exp time when caching is enabled and the token has exp but no iat. In src/verifier.js, cacheSet derives the exp cache deadline only when iat is present, so the cache falls back to cacheTTL, and a later cache hit returns the saved payload before verifyToken rechecks expiration. An attacker who can replay the same cached bearer token can extend access until the cache entry expires, but cannot forge a token through this issue. This issue is fixed in version 6.3.4.
Title fast-jwt: Verifier cache accepts expired JWTs without iat.
Weaknesses CWE-613
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T21:41:55.342Z

Reserved: 2026-10-08T17:21:52.975Z

Link: CVE-2026-107719

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-08T22:17:27.913

Modified: 2026-10-08T22:17:28.053

Link: CVE-2026-107719

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T23:30:12Z

Weaknesses
  • CWE-613

    Insufficient Session Expiration