Security Flaw in Fast JSON Web Token Implementation by NearForm
CVE-2026-107721
5.9MEDIUM
What is CVE-2026-107721?
A vulnerability exists in the fast-jwt library that allows for improper validation of JSON Web Tokens due to the acceptance of an infinite clock tolerance value in the createVerifier method. This flaw means that expired or not-yet-active tokens could be accepted, which poses a significant risk in token management. The weakness arises from the lack of checks for finiteness in the option validation process and allows for the creation of a valid cache entry that may not be evicted until the cache is refreshed. Application administrators are required to be vigilant about their configurations to avoid exploitation. This issue is addressed in version 6.3.0.
Affected Version(s)
fast-jwt < 6.3.0
