Low · 2.5 Node.js & npm GHSA-x937-hj6v-793p CVE-2026-107719
fast-jwt: Verifier cache accepts expired JWTs (CVE-2026-107719)
fast-jwt's createVerifier cache can accept a previously valid signed JWT after its exp time when caching is enabled and the token has exp but no iat. The issue is fixed in 6.3.4. (Sources: OSV, NVD)
AI summary
CVE-2026-107719 affects the fast-jwt library. When verifier caching is enabled, tokens that include exp but omit iat can be returned from the verifier cache after their exp time, extending access until the cache entry expires. A fix is available in 6.3.4. (Sources: OSV, NVD)
What happened
fast-jwt's createVerifier cache can continue accepting a previously valid, signed JWT after its exp time when caching is enabled and the token contains exp but no iat. A later cache hit returns the saved payload before verifyToken rechecks expiration, allowing replayed tokens to remain accepted until the cache entry expires. The library cannot be used to forge tokens through this issue. (Sources: OSV, NVD)
Technical cause
In src/verifier.js the cacheSet logic derives the cache deadline from the token's iat and exp only when iat is present. If iat is missing the code falls back to a generic cacheTTL, so expiration is not enforced per-token at cache-hit time. That fallback lets a cached payload be returned without a fresh expiration check. (Source: OSV)
Why it matters
An attacker who can replay the same cached bearer token can extend access until the cache entry expires. The issue does not enable forging tokens, but it increases the effective lifetime of an otherwise-expired token when caching is used. (Source: OSV)
Who is affected
Applications using the fast-jwt library with verifier caching enabled and that accept JWTs which include an exp claim but omit an iat claim are affected. The report covers the fast-jwt package in the npm ecosystem. (Sources: OSV, NVD)
Discovery and timeline
The vulnerability was published in OSV and NVD on 2026-10-08 (OSV) / 2026-10-08 (NVD). The advisory entries used here are the OSV record and the NVD entry. No additional discovery details are provided in those sources. (Sources: OSV, NVD)
Affected versions
The advisory lists fast-jwt as affected from 0 up to being fixed in 6.3.4. Users should treat versions earlier than 6.3.4 as impacted. (Source: OSV)
Fixes and mitigation
A fix is available in 6.3.4. If you cannot upgrade immediately, consider disabling verifier caching, rejecting tokens that lack an iat claim, or reducing the verifier cache TTL so that cached entries expire more quickly. Implement and test any mitigation to ensure it does not break your authentication flow. (Sources: OSV, NVD)
Recommended action
Upgrade fast-jwt to 6.3.4. If you cannot upgrade right away, disable verifier caching or ensure incoming tokens include an iat claim and shorten cache TTLs until you can apply the vendor update. Verify behavior in a staging environment before deploying to production. (Sources: OSV, NVD)
PatchBriefing score
2.5 / 10 · Low
Official CVSS: 4.2
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Why this score
CVSS v3.1 base score is 4.2 (AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N) which indicates a low-to-medium impact for confidentiality and integrity. The PatchWire score is 2.5; contributing factors include the CVSS base score and that no public exploit or evidence of active exploitation was reported. The vulnerability requires a replayable bearer token and caching to be effective, and it cannot be used to forge tokens. (Sources: OSV, NVD)
Affected versions
- fast-jwt ≥ 0 < 6.3.4
- vulnerable
- ≥ 6.3.4
- patched
Reported fixes
A fix is available in 6.3.4. If you cannot upgrade immediately, consider disabling verifier caching, rejecting tokens that lack an iat claim, or reducing the verifier cache TTL so that cached entries expire more quickly. Implement and test any mitigation to ensure it does not break your authentication flow. (Sources: OSV, NVD)
How this was built
2 source records were collected, matched and used to prepare the report above.
-
OSV.dev database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email