CVE-2026-107719: Session Expiration Bypass in fast-jwt via Verifier Cache
Vulnerability ID: CVE-2026-107719
CVSS Score: 4.2
Published: 2026-10-08
An authentication bypass vulnerability in NearForm's fast-jwt before version 6.3.4 allows attackers to replay expired tokens due to an error in the verifier's cache expiration logic. When caching is enabled, the cache TTL defaults to 10 minutes instead of honoring the token's exp claim if the token lacks an iat claim.
TL;DR
A validation flaw in fast-jwt's cache logic allows expired tokens without an iat claim to bypass verification and remain valid for up to 10 minutes.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-613: Insufficient Session Expiration
- Attack Vector: Network (Remote)
- CVSS Score: 4.2 (Medium)
- Exploit Status: poc
- KEV Status: Not Listed
- Affected Component: src/verifier.js (cacheSet function)
Affected Systems
- Applications utilizing nearform/fast-jwt with verification caching enabled
-
fast-jwt: < 6.3.4 (Fixed in:
6.3.4)
Code Analysis
Commit: fc1ddbb
Decouple exp evaluation from iat in cache calculation and use Math.min to apply the strictest expiration.
Commit: e7fe8b0
Secondary hardening for empty key handling and non-finite warnings in signer.
Commit: e84d4b5
Documentation update correcting README ms options.
Mitigation Strategies
- Upgrade fast-jwt to version 6.3.4 or higher.
- Disable verifier caching by setting cache: false in createVerifier options.
- Enforce inclusion of the iat claim in token payloads generation.
Remediation Steps:
- Identify all Node.js projects utilizing fast-jwt by auditing package.json files.
- Run 'npm install fast-jwt@6.3.4' or 'yarn add fast-jwt@6.3.4' in target repositories.
- If upgrades are delayed, locate instances of 'createVerifier' and temporarily configure 'cache: false'.
- Ensure signers do not configure 'noTimestamp: true' during token minting.
References
- GitHub Security Advisory: Session expiration bypass when using cache
- CVE.org Record
- fast-jwt GitHub Repository
Read the full report for CVE-2026-107719 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)