Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-x937-hj6v-793p | fast-jwt: Verifier cache accepts expired JWTs without iat. |
Thu, 08 Oct 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.4, the fast-jwt createVerifier cache can continue accepting a previously valid, signed JWT after its exp time when caching is enabled and the token has exp but no iat. In src/verifier.js, cacheSet derives the exp cache deadline only when iat is present, so the cache falls back to cacheTTL, and a later cache hit returns the saved payload before verifyToken rechecks expiration. An attacker who can replay the same cached bearer token can extend access until the cache entry expires, but cannot forge a token through this issue. This issue is fixed in version 6.3.4. | |
| Title | fast-jwt: Verifier cache accepts expired JWTs without iat. | |
| Weaknesses | CWE-613 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-08T21:41:55.342Z
Reserved: 2026-10-08T17:21:52.975Z
Link: CVE-2026-107719
No data.
Status : Deferred
Published: 2026-10-08T22:17:27.913
Modified: 2026-10-08T22:17:28.053
Link: CVE-2026-107719
No data.
OpenCVE Enrichment
No data.
-
CWE-613
Insufficient Session Expiration
Github GHSA