DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-107719: CVE-2026-107719: Session Expiration Bypass in fast-jwt via Verifier Cache

CVE-2026-107719: Session Expiration Bypass in fast-jwt via Verifier Cache

Vulnerability ID: CVE-2026-107719
CVSS Score: 4.2
Published: 2026-10-08

An authentication bypass vulnerability in NearForm's fast-jwt before version 6.3.4 allows attackers to replay expired tokens due to an error in the verifier's cache expiration logic. When caching is enabled, the cache TTL defaults to 10 minutes instead of honoring the token's exp claim if the token lacks an iat claim.

TL;DR

A validation flaw in fast-jwt's cache logic allows expired tokens without an iat claim to bypass verification and remain valid for up to 10 minutes.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-613: Insufficient Session Expiration
  • Attack Vector: Network (Remote)
  • CVSS Score: 4.2 (Medium)
  • Exploit Status: poc
  • KEV Status: Not Listed
  • Affected Component: src/verifier.js (cacheSet function)

Affected Systems

  • Applications utilizing nearform/fast-jwt with verification caching enabled
  • fast-jwt: < 6.3.4 (Fixed in: 6.3.4)

Code Analysis

Commit: fc1ddbb

Decouple exp evaluation from iat in cache calculation and use Math.min to apply the strictest expiration.

Commit: e7fe8b0

Secondary hardening for empty key handling and non-finite warnings in signer.

Commit: e84d4b5

Documentation update correcting README ms options.

Mitigation Strategies

  • Upgrade fast-jwt to version 6.3.4 or higher.
  • Disable verifier caching by setting cache: false in createVerifier options.
  • Enforce inclusion of the iat claim in token payloads generation.

Remediation Steps:

  1. Identify all Node.js projects utilizing fast-jwt by auditing package.json files.
  2. Run 'npm install fast-jwt@6.3.4' or 'yarn add fast-jwt@6.3.4' in target repositories.
  3. If upgrades are delayed, locate instances of 'createVerifier' and temporarily configure 'cache: false'.
  4. Ensure signers do not configure 'noTimestamp: true' during token minting.

References


Read the full report for CVE-2026-107719 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)