JSON Web Token Plugin Vulnerability in Fastify by Fastify
CVE-2026-107275
What is CVE-2026-107275?
@fastify/jwt, a JSON Web Token plugin for Fastify, has a vulnerability in versions prior to 10.2.3. The plugin fails to properly handle invalid time spans passed to expiresIn, notBefore, or maxAge parameters. Instead of rejecting these invalid inputs, the plugin silently drops them. This results in the creation of tokens lacking an expiration claim, which can lead to security risks by allowing tokens to remain valid indefinitely. On the verification side, this issue can allow tokens that should be expired to be accepted when they are not correctly enforced by the configured maxAge. Users are advised to upgrade to version 10.2.3 or later to mitigate these risks. Alternatively, it is suggested to pass these time options as a number of seconds or ensure that any time-span string is verified to parse to a finite value.
Affected Version(s)
@fastify/jwt 0 < 10.2.3
@fastify/jwt 10.2.3
