CVE-2026-107719
Deferred Deferred - Pending Action

Fast JWT Verifier Cache Bypass via Expired Token

Vulnerability report for CVE-2026-107719, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.4, the fast-jwt createVerifier cache can continue accepting a previously valid, signed JWT after its exp time when caching is enabled and the token has exp but no iat. In src/verifier.js, cacheSet derives the exp cache deadline only when iat is present, so the cache falls back to cacheTTL, and a later cache hit returns the saved payload before verifyToken rechecks expiration. An attacker who can replay the same cached bearer token can extend access until the cache entry expires, but cannot forge a token through this issue. This issue is fixed in version 6.3.4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
nearform fast-jwt < 6.3.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-613 According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects fast-jwt versions before 6.3.4. When caching is enabled and a JWT token has an expiration time but no issued-at time, the cache may accept an expired token. The cache deadline is only set if iat is present, so it falls back to a time-to-live value. An attacker can replay a cached token to extend access until the cache entry expires, but cannot forge new tokens.

Detection Guidance

Detecting this vulnerability requires checking if your fast-jwt library version is below 6.3.4. Run npm list fast-jwt or check your package.json to verify the installed version. If the version is older, the vulnerability may be present.

Impact Analysis

If you use fast-jwt with caching enabled and tokens lack an issued-at claim, an attacker could replay a valid but expired token to gain unauthorized access. This could lead to data exposure or privilege escalation until the cache entry expires.

Compliance Impact

This vulnerability could violate compliance by allowing unauthorized access to sensitive data, potentially breaching GDPR's data protection principles or HIPAA's access controls. Unauthorized token replay may lead to data leaks or improper access.

Mitigation Strategies

Upgrade fast-jwt to version 6.3.4 or later immediately. Use npm update fast-jwt or adjust your package.json to specify version 6.3.4 or higher. This fixes the caching issue that allows token replay.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107719. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart