Impact
This vulnerability affects the fast-jwt library, where the verifier cache does not enforce expiration for tokens lacking an iat claim. When caching is enabled, an attacker who replays a previously valid, but now expired, bearer token can obtain access until the cached entry expires. Although the attacker cannot forge a token, the ability to extend the life of an existing token permits continued unauthorized access for the cache duration.
Affected Systems
Vendors using the fast-jwt library released by nearform are impacted. Any installation utilizing pre‑6.3.4 versions of fast‑jwt is vulnerable. The issue was resolved in release 6.3.4.
Risk and Exploitability
This vulnerability has a CVSS of 4.2, indicating moderate risk. The EPSS score is not available, so overall exploit probability cannot be quantified. Since it is not listed in the CISA KEV catalog, there are no current known large‑scale exploitation campaigns documented. An attacker who can inject a cached bearer token into an HTTP request is able to bypass expiration, assuming network visibility to the application. Mitigation directly involves updating to a patched version or disabling the verifier cache.
OpenCVE Enrichment
Github GHSA