JSON Web Token Plugin Vulnerability in Fastify by Fastify
CVE-2026-107275

6.8MEDIUM

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107275?

@fastify/jwt, a JSON Web Token plugin for Fastify, has a vulnerability in versions prior to 10.2.3. The plugin fails to properly handle invalid time spans passed to expiresIn, notBefore, or maxAge parameters. Instead of rejecting these invalid inputs, the plugin silently drops them. This results in the creation of tokens lacking an expiration claim, which can lead to security risks by allowing tokens to remain valid indefinitely. On the verification side, this issue can allow tokens that should be expired to be accepted when they are not correctly enforced by the configured maxAge. Users are advised to upgrade to version 10.2.3 or later to mitigate these risks. Alternatively, it is suggested to pass these time options as a number of seconds or ensure that any time-span string is verified to parse to a finite value.

Affected Version(s)

@fastify/jwt 0 < 10.2.3

@fastify/jwt 10.2.3

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

kagebunsher
mcollina
UlisesGascon
.