CVE-2026-107721
Deferred Deferred - Pending Action

Denial of Service via Infinite clockTolerance in fast-jwt

Vulnerability report for CVE-2026-107721, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.0, fast-jwt createVerifier accepts Infinity for clockTolerance because its option validation checks type and negativity but not finiteness. In validateClaimDateValue, infinite positive and negative modifiers make exp and nbf comparisons always pass, allowing expired or not-yet-active tokens to be accepted. The verifier cache also derives infinite bounds, so entries created under this configuration can remain valid until eviction. Exploitation requires an application administrator or equivalent configuration path to set clockTolerance to Infinity. This issue is fixed in version 6.3.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
nearform fast-jwt < 6.3.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-613 According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
CWE-682 The product performs a calculation that generates incorrect or unintended results that are later used in security-critical decisions or resource management.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects fast-jwt, a fast JSON Web Token (JWT) implementation. It allows an attacker to bypass token expiration checks by setting clockTolerance to Infinity. This makes expired or not-yet-active tokens appear valid, as comparisons for exp and nbf claims always pass. The issue is fixed in version 6.3.0.

Detection Guidance

Check if fast-jwt version is below 6.3.0 by running npm list fast-jwt or checking package.json. Inspect application configurations for clockTolerance set to Infinity in JWT verifier settings.

Impact Analysis

If exploited, this vulnerability could allow unauthorized access to systems or data protected by JWT tokens. Attackers could use expired or invalid tokens to gain access, potentially leading to data breaches or unauthorized actions. Exploitation requires administrative access to configure clockTolerance to Infinity.

Compliance Impact

This vulnerability could lead to unauthorized access, violating data protection principles in GDPR and HIPAA. Non-compliance risks include fines, legal penalties, and reputational damage due to potential data breaches or unauthorized data exposure.

Mitigation Strategies

Upgrade fast-jwt to version 6.3.0 or later. Review and update JWT verifier configurations to ensure clockTolerance is set to a finite value. Remove any instances where clockTolerance is set to Infinity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107721. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart