Security Flaw in Fast JSON Web Token Implementation by NearForm
CVE-2026-107721

5.9MEDIUM

Key Information:

Vendor

Nearform

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107721?

A vulnerability exists in the fast-jwt library that allows for improper validation of JSON Web Tokens due to the acceptance of an infinite clock tolerance value in the createVerifier method. This flaw means that expired or not-yet-active tokens could be accepted, which poses a significant risk in token management. The weakness arises from the lack of checks for finiteness in the option validation process and allows for the creation of a valid cache entry that may not be evicted until the cache is refreshed. Application administrators are required to be vigilant about their configurations to avoid exploitation. This issue is addressed in version 6.3.0.

Affected Version(s)

fast-jwt < 6.3.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.