fast-jwt, Authentication Bypass, CVE-2026-107719 (Medium) -DC-Oct2026-2994

Listen to this Post

The vulnerability stems from how the fast-jwt library computes expiration cache deadlines within the verification module. Specifically, the cache-setting logic inside src/verifier.js conditions the derivation of expiration cache deadlines on the presence of the optional “issued at” claim known as iat. When a valid JSON Web Token contains an expiration time claim exp but lacks an iat claim, the verification caching mechanism fails to configure the token-specific expiration deadline. Instead, the implementation falls back to a generic default cache time-to-live window. Because subsequent lookups query the cache before executing token decoding or validation checks, an expired token continues to be treated as valid and returns the previously cached payload claims until the fallback cache time-to-live expires entirely.

DailyCVE Form:

Platform: Node.js
Version: <= 6.3.3
Vulnerability : Expiration Bypass
Severity: Medium
date: 2026-10-09

Prediction: 2026-10-09

What Undercode Say

Bash Commands and Codes

npm install [email protected]
node -e "const {createVerifier} = require('fast-jwt');"

Exploit: (Educational Purposes!)

const { createSigner, createVerifier } = require('fast-jwt')
const key = 'audit-secret'
const sign = createSigner({ key, algorithm: 'HS256', noTimestamp: true })
const token = sign({ sub: 'alice', exp: Math.floor(Date.now() / 1000) + 1 })
const verify = createVerifier({ key, algorithms: ['HS256'], cache: true })
verify(token)

Protection: from this CVE

Upgrade the `fast-jwt` package to version 6.3.4 or higher where the cache deadline computation correctly evaluates the expiration claim independently of the issued-at claim.

Impact:

Allows attackers to replay previously valid bearer tokens after their intended expiration time if caching is enabled and the token omits the optional issued-at claim, undermining session boundaries.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top