CVE-2026-107275
Received Received - Intake

Improper Token Expiration Handling in Fastify JWT Plugin

Vulnerability report for CVE-2026-107275, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: openjs

Description

@fastify/jwt is a JSON Web Token plugin for the Fastify web framework. In versions before 10.2.3, a time span passed to expiresIn, notBefore, or maxAge that the plugin's parser cannot read, such as a compound span, a month unit, an ISO 8601 duration, a decimal comma, or a value with surrounding whitespace, is silently dropped instead of refused. On the signing path this produces a token with no expiration claim that never expires, and on the verification path a configured maxAge stops being enforced, so a token that should be rejected for age is accepted. The issue is fixed in @fastify/jwt 10.2.3, and users should upgrade to 10.2.3 or later. As a workaround, pass these options as a number of seconds, or verify that any time-span string parses to a finite value before relying on it.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
@fastify/jwt @fastify/jwt 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-613 According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
CWE-754 The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.
CWE-390 The product detects a specific error, but takes no actions to handle the error.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the @fastify/jwt library before version 10.2.3. When time spans like '1h30m' or '90m' are passed to options such as expiresIn, notBefore, or maxAge, the library silently drops unparseable strings instead of rejecting them. This causes tokens to be generated without an expiration claim or bypasses maxAge enforcement during verification, allowing tokens to persist indefinitely.

Detection Guidance

Check the version of @fastify/jwt in your project using npm list @fastify/jwt or grep -r "@fastify/jwt" package.json. If the version is below 10.2.3, the system is vulnerable. Review application code for usage of expiresIn, notBefore, or maxAge with non-numeric values.

Impact Analysis

Attackers could exploit this to create tokens that never expire, gaining unauthorized long-term access to systems. Applications using user-controlled values in these options may also experience per-call overrides, extending token lifetimes beyond configured defaults. This could lead to persistent unauthorized access or data breaches.

Compliance Impact

This vulnerability could violate compliance requirements for data protection and session management. GDPR requires proper data retention and access controls, while HIPAA mandates secure authentication and session expiration. Unlimited token persistence may lead to unauthorized access, risking non-compliance with these regulations.

Mitigation Strategies

Upgrade @fastify/jwt to version 10.2.3 or later immediately. Replace time-span strings with numeric seconds for expiresIn, notBefore, and maxAge. Validate all time-span inputs before use to ensure they parse correctly.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107275. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart