Listen to this Post
The fast-jwt library contains a critical security flaw in its token verification option processing where passing an infinite value for the clockTolerance option results in the complete bypass of both expiration (exp) and not-before (nbf) claim validations. When clockTolerance is set to Infinity, the internal date comparison calculations evaluate to positive and negative infinity respectively, causing checks to always yield true regardless of whether a token has expired or is not yet active. Furthermore, this option flows directly into the verifier’s LRU cache creation, contaminating cached entries with infinite validity windows. Consequently, any tokens verified during a debug or misconfigured window remain permanently cached as valid until standard LRU eviction occurs, subverting token time-to-live boundaries and security guarantees.
DailyCVE Form:
Platform: fast-jwt
Version: <= 6.2.4
Vulnerability : Expiration Bypass
Severity: Critical
date: 2026-06-03
Prediction: 2026-06-04
What Undercode Say
The fast-jwt library fails to validate whether options such as clockTolerance are finite numbers. While the token signer side correctly enforces `Number.isFinite()` on time properties like expiresIn and notBefore, the verifier side completely lacks this check. Consequently, passing `Infinity` bypasses temporal validation boundaries entirely, leaving security-critical expiration checks vulnerable to structural misconfigurations or sentinel value pollution.
Bash Commands and Codes
npm install [email protected]
const { createSigner, createVerifier } = require('fast-jwt');
const secret = 'test-secret-with-enough-length-to-pass';
const sign = createSigner({ key: secret, algorithm: 'HS256' });
const expiredToken = sign({
sub: 'alice',
exp: Math.floor(Date.now()/1000) - 1800
});
const verifier = createVerifier({ key: secret, clockTolerance: Infinity });
console.log(verifier(expiredToken));
Exploit: (Educational Purposes!)
An attacker or compromised environment configuration can leverage an infinite clock tolerance value to force acceptance of heavily expired or prematurely issued JSON Web Tokens. Because the validation logic applies a modifier additively using the `clockTolerance` value, feeding `Infinity` turns the target comparison into an unconditional pass. In systems where configuration values are parsed dynamically from environment variables or JSON payloads, passing string configurations like `”Infinity”` can silently disable time enforcement mechanisms across production services.
Protection: from this CVE
Upgrade the fast-jwt library to version 6.2.5 or higher where strict type and finiteness checking via `Number.isFinite()` is enforced on option parameters. Alternatively, apply explicit code defenses to ensure temporal parameters are restricted to positive finite numbers and avoid passing unvalidated inputs or sentinel values into security verifiers.
Impact
Successful exploitation leads to a total compromise of token lifecycle security. Expired session tokens, revoked credentials, or premature tokens are processed as entirely legitimate, enabling unauthorized access to protected routes, persistent session hijacking via corrupted cache entries, and bypass of core authentication time constraints.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

