Token Expiration Flaw in fast-jwt by Nearform
CVE-2026-107719

4.2MEDIUM

Key Information:

Vendor

Nearform

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107719?

The fast-jwt library, developed by Nearform, has a vulnerability that allows a cached JSON Web Token (JWT) to remain valid beyond its expiration time under specific conditions. Before version 6.3.4, the createVerifier function's cache logic fails to properly handle tokens that lack an issued-at (iat) claim. This mismanagement allows an attacker to replay a valid bearer token even after its expiration time has passed. As a result, an attacker could extend unauthorized access until the cached entry naturally expires. Ensuring that applications using fast-jwt are updated to version 6.3.4 or higher is essential to mitigate this risk.

Affected Version(s)

fast-jwt < 6.3.4

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.