Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | @fastify/jwt is a JSON Web Token plugin for the Fastify web framework. In versions before 10.2.3, a time span passed to expiresIn, notBefore, or maxAge that the plugin's parser cannot read, such as a compound span, a month unit, an ISO 8601 duration, a decimal comma, or a value with surrounding whitespace, is silently dropped instead of refused. On the signing path this produces a token with no expiration claim that never expires, and on the verification path a configured maxAge stops being enforced, so a token that should be rejected for age is accepted. The issue is fixed in @fastify/jwt 10.2.3, and users should upgrade to 10.2.3 or later. As a workaround, pass these options as a number of seconds, or verify that any time-span string parses to a finite value before relying on it. | |
| Title | @fastify/jwt vulnerable to missing token expiration when temporal options cannot be parsed | |
| Weaknesses | CWE-390 CWE-613 CWE-754 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: openjs
Published:
Updated: 2026-10-08T11:05:40.492Z
Reserved: 2026-10-07T15:36:05.942Z
Link: CVE-2026-107275
No data.
Status : Received
Published: 2026-10-08T12:17:14.553
Modified: 2026-10-08T12:17:14.553
Link: CVE-2026-107275
No data.
OpenCVE Enrichment
Updated: 2026-10-08T12:45:18Z