Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Low · 2.5 Node.js & npm GHSA-x937-hj6v-793p CVE-2026-107719

fast-jwt: Verifier cache accepts expired JWTs (CVE-2026-107719)

fast-jwt's createVerifier cache can accept a previously valid signed JWT after its exp time when caching is enabled and the token has exp but no iat. The issue is fixed in 6.3.4. (Sources: OSV, NVD)

Synthesized by AI from 2 sources · updated 1 hour ago

AI summary

CVE-2026-107719 affects the fast-jwt library. When verifier caching is enabled, tokens that include exp but omit iat can be returned from the verifier cache after their exp time, extending access until the cache entry expires. A fix is available in 6.3.4. (Sources: OSV, NVD)

What happened

fast-jwt's createVerifier cache can continue accepting a previously valid, signed JWT after its exp time when caching is enabled and the token contains exp but no iat. A later cache hit returns the saved payload before verifyToken rechecks expiration, allowing replayed tokens to remain accepted until the cache entry expires. The library cannot be used to forge tokens through this issue. (Sources: OSV, NVD)

Technical cause

In src/verifier.js the cacheSet logic derives the cache deadline from the token's iat and exp only when iat is present. If iat is missing the code falls back to a generic cacheTTL, so expiration is not enforced per-token at cache-hit time. That fallback lets a cached payload be returned without a fresh expiration check. (Source: OSV)

Why it matters

An attacker who can replay the same cached bearer token can extend access until the cache entry expires. The issue does not enable forging tokens, but it increases the effective lifetime of an otherwise-expired token when caching is used. (Source: OSV)

Who is affected

Applications using the fast-jwt library with verifier caching enabled and that accept JWTs which include an exp claim but omit an iat claim are affected. The report covers the fast-jwt package in the npm ecosystem. (Sources: OSV, NVD)

Discovery and timeline

The vulnerability was published in OSV and NVD on 2026-10-08 (OSV) / 2026-10-08 (NVD). The advisory entries used here are the OSV record and the NVD entry. No additional discovery details are provided in those sources. (Sources: OSV, NVD)

Affected versions

The advisory lists fast-jwt as affected from 0 up to being fixed in 6.3.4. Users should treat versions earlier than 6.3.4 as impacted. (Source: OSV)

Fixes and mitigation

A fix is available in 6.3.4. If you cannot upgrade immediately, consider disabling verifier caching, rejecting tokens that lack an iat claim, or reducing the verifier cache TTL so that cached entries expire more quickly. Implement and test any mitigation to ensure it does not break your authentication flow. (Sources: OSV, NVD)

Recommended action

Upgrade fast-jwt to 6.3.4. If you cannot upgrade right away, disable verifier caching or ensure incoming tokens include an iat claim and shorten cache TTLs until you can apply the vendor update. Verify behavior in a staging environment before deploying to production. (Sources: OSV, NVD)

PatchBriefing score

2.5 / 10 · Low

Official CVSS: 4.2

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Why this score

CVSS v3.1 base score is 4.2 (AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N) which indicates a low-to-medium impact for confidentiality and integrity. The PatchWire score is 2.5; contributing factors include the CVSS base score and that no public exploit or evidence of active exploitation was reported. The vulnerability requires a replayable bearer token and caching to be effective, and it cannot be used to forge tokens. (Sources: OSV, NVD)

Affected versions

fast-jwt ≥ 0 < 6.3.4
vulnerable
≥ 6.3.4
patched

Reported fixes

A fix is available in 6.3.4. If you cannot upgrade immediately, consider disabling verifier caching, rejecting tokens that lack an iat claim, or reducing the verifier cache TTL so that cached entries expire more quickly. Implement and test any mitigation to ensure it does not break your authentication flow. (Sources: OSV, NVD)

How this was built

2 source records were collected, matched and used to prepare the report above.

  • OSV.dev database
  • NVD (NIST) database
Unified report
fast-jwt: Verifier cache accepts expired JWTs (CVE-2026-107719)
1 article · 2 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email