Listen to this Post
The vulnerability stems from how the fast-jwt library computes expiration cache deadlines within the verification module. Specifically, the cache-setting logic inside src/verifier.js conditions the derivation of expiration cache deadlines on the presence of the optional “issued at” claim known as iat. When a valid JSON Web Token contains an expiration time claim exp but lacks an iat claim, the verification caching mechanism fails to configure the token-specific expiration deadline. Instead, the implementation falls back to a generic default cache time-to-live window. Because subsequent lookups query the cache before executing token decoding or validation checks, an expired token continues to be treated as valid and returns the previously cached payload claims until the fallback cache time-to-live expires entirely.
DailyCVE Form:
Platform: Node.js
Version: <= 6.3.3
Vulnerability : Expiration Bypass
Severity: Medium
date: 2026-10-09
Prediction: 2026-10-09
What Undercode Say
Bash Commands and Codes
npm install [email protected] node -e "const {createVerifier} = require('fast-jwt');"
Exploit: (Educational Purposes!)
const { createSigner, createVerifier } = require('fast-jwt')
const key = 'audit-secret'
const sign = createSigner({ key, algorithm: 'HS256', noTimestamp: true })
const token = sign({ sub: 'alice', exp: Math.floor(Date.now() / 1000) + 1 })
const verify = createVerifier({ key, algorithms: ['HS256'], cache: true })
verify(token)
Protection: from this CVE
Upgrade the `fast-jwt` package to version 6.3.4 or higher where the cache deadline computation correctly evaluates the expiration claim independently of the issued-at claim.
Impact:
Allows attackers to replay previously valid bearer tokens after their intended expiration time if caching is enabled and the token omits the optional issued-at claim, undermining session boundaries.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

