Low · 3.4 Node.js & npm GHSA-687g-22h4-j4w4 CVE-2026-107721
fast-jwt: clockTolerance = Infinity bypasses exp/nbf and persists in verifier cache (CVE-2026-107721)
fast-jwt accepted Infinity for clockTolerance, letting exp and nbf checks always pass and allowing expired or not-yet-active JWTs to be accepted. Verifier cache entries created under that configuration can remain valid until eviction. The issue is fixed in 6.3.0. [CVE-2026-107721, GHSA-687g-22h4-j4w4]
AI summary
A vulnerability in fast-jwt allows Infinity to be used as clockTolerance when creating a verifier, which causes exp and nbf validations to be bypassed and can persist via the verifier cache. Fixed in 6.3.0. [CVE-2026-107721, GHSA-687g-22h4-j4w4]
What happened
fast-jwt's verifier construction accepted Infinity for the clockTolerance option because validation checked type and negativity but did not require finiteness. When clockTolerance is Infinite, the library's date-claim comparisons (exp and nbf) always pass, so expired or not-yet-active tokens can be accepted. Verifier cache entries created with those infinite bounds can remain valid until they are evicted. [Sources: 4098, 31978]
Technical cause
The option validation allowed Infinity by checking only type and whether the value was negative, omitting a finiteness check. In validateClaimDateValue, infinite positive or negative modifiers make exp and nbf comparisons always succeed. The same infinite bounds are used when populating the verifier cache, so entries created under that configuration inherit the ineffective checks. [Sources: 4098, 31978]
Why it matters
Bypassing exp and nbf validation means tokens that should be expired or not yet valid can be accepted, undermining token-based authentication and authorization. The published CVSS base score is 5.9 with vector CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N, indicating network-accessible codepaths but requiring high privileges to exploit; the vector shows high confidentiality and integrity impact. The verifier cache behavior can prolong the window in which affected tokens are accepted. [Sources: 4098, 31978]
Who is affected
Applications that use the fast-jwt npm package and that allow an administrator or equivalent configuration path to set clockTolerance to Infinity are at risk. Exploitation requires that privileged configuration capability. [Sources: 4098, 31978]
Discovery and timeline
The issue was published to OSV.dev on 2026-10-08T22:02:02+02:00 and appears in NVD as CVE-2026-107721 (published 2026-10-08T22:17:28+02:00). The advisory record was modified on 2026-10-09T16:17:23+02:00. [Sources: 4098, 31978]
Affected versions
All fast-jwt releases from 0 up to but not including 6.3.0 are affected. The package's fixed version is 6.3.0. [Sources: 4098]
Fixes and mitigation
A vendor fix is available in 6.3.0. If you can apply updates, upgrade fast-jwt to 6.3.0. Where upgrades are not immediately possible, avoid configuring clockTolerance as Infinity; restrict administrative configuration paths that could set that value. Because verifier cache entries created under an Infinity configuration can remain valid until eviction, clear or evict verifier cache entries (for example by restarting verifier processes or using application-specific cache controls) to remove entries created with infinite bounds. [Sources: 4098, 31978]
Recommended action
1) Update fast-jwt to 6.3.0. 2) Audit configuration interfaces and remove any capability that allows clockTolerance to be set to Infinity. 3) If you previously allowed clockTolerance = Infinity, clear or evict the verifier cache (restart verifier processes or use cache controls) to remove entries created under that setting. 4) After updating, confirm normal exp/nbf behavior in a test environment. [Sources: 4098, 31978]
PatchBriefing score
3.4 / 10 · Low
Official CVSS: 5.9
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
Why this score
The advisory lists a CVSS v3.1 base score of 5.9 (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N). That vector indicates network-accessible codepaths but exploitation requires high privileges (PR:H) and has high attack complexity (AC:H); no user interaction is required (UI:N). Confidentiality and integrity impacts are rated high, while availability impact is none. PatchWire's composite score for this advisory is 3.4, which combines the CVSS base with other factors such as the absence of public exploits and the need for privileged access. [Sources: 4098, 31978]
Affected versions
- fast-jwt ≥ 0 < 6.3.0
- vulnerable
- ≥ 6.3.0
- patched
Reported fixes
A vendor fix is available in 6.3.0. If you can apply updates, upgrade fast-jwt to 6.3.0. Where upgrades are not immediately possible, avoid configuring clockTolerance as Infinity; restrict administrative configuration paths that could set that value. Because verifier cache entries created under an Infinity configuration can remain valid until eviction, clear or evict verifier cache entries (for example by restarting verifier processes or using application-specific cache controls) to remove entries created with infinite bounds. [Sources: 4098, 31978]
How this was built
2 source records were collected, matched and used to prepare the report above.
-
OSV.dev database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email