Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Low · 3.4 Node.js & npm GHSA-687g-22h4-j4w4 CVE-2026-107721

fast-jwt: clockTolerance = Infinity bypasses exp/nbf and persists in verifier cache (CVE-2026-107721)

fast-jwt accepted Infinity for clockTolerance, letting exp and nbf checks always pass and allowing expired or not-yet-active JWTs to be accepted. Verifier cache entries created under that configuration can remain valid until eviction. The issue is fixed in 6.3.0. [CVE-2026-107721, GHSA-687g-22h4-j4w4]

Synthesized by AI from 2 sources · updated 1 hour ago

AI summary

A vulnerability in fast-jwt allows Infinity to be used as clockTolerance when creating a verifier, which causes exp and nbf validations to be bypassed and can persist via the verifier cache. Fixed in 6.3.0. [CVE-2026-107721, GHSA-687g-22h4-j4w4]

What happened

fast-jwt's verifier construction accepted Infinity for the clockTolerance option because validation checked type and negativity but did not require finiteness. When clockTolerance is Infinite, the library's date-claim comparisons (exp and nbf) always pass, so expired or not-yet-active tokens can be accepted. Verifier cache entries created with those infinite bounds can remain valid until they are evicted. [Sources: 4098, 31978]

Technical cause

The option validation allowed Infinity by checking only type and whether the value was negative, omitting a finiteness check. In validateClaimDateValue, infinite positive or negative modifiers make exp and nbf comparisons always succeed. The same infinite bounds are used when populating the verifier cache, so entries created under that configuration inherit the ineffective checks. [Sources: 4098, 31978]

Why it matters

Bypassing exp and nbf validation means tokens that should be expired or not yet valid can be accepted, undermining token-based authentication and authorization. The published CVSS base score is 5.9 with vector CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N, indicating network-accessible codepaths but requiring high privileges to exploit; the vector shows high confidentiality and integrity impact. The verifier cache behavior can prolong the window in which affected tokens are accepted. [Sources: 4098, 31978]

Who is affected

Applications that use the fast-jwt npm package and that allow an administrator or equivalent configuration path to set clockTolerance to Infinity are at risk. Exploitation requires that privileged configuration capability. [Sources: 4098, 31978]

Discovery and timeline

The issue was published to OSV.dev on 2026-10-08T22:02:02+02:00 and appears in NVD as CVE-2026-107721 (published 2026-10-08T22:17:28+02:00). The advisory record was modified on 2026-10-09T16:17:23+02:00. [Sources: 4098, 31978]

Affected versions

All fast-jwt releases from 0 up to but not including 6.3.0 are affected. The package's fixed version is 6.3.0. [Sources: 4098]

Fixes and mitigation

A vendor fix is available in 6.3.0. If you can apply updates, upgrade fast-jwt to 6.3.0. Where upgrades are not immediately possible, avoid configuring clockTolerance as Infinity; restrict administrative configuration paths that could set that value. Because verifier cache entries created under an Infinity configuration can remain valid until eviction, clear or evict verifier cache entries (for example by restarting verifier processes or using application-specific cache controls) to remove entries created with infinite bounds. [Sources: 4098, 31978]

Recommended action

1) Update fast-jwt to 6.3.0. 2) Audit configuration interfaces and remove any capability that allows clockTolerance to be set to Infinity. 3) If you previously allowed clockTolerance = Infinity, clear or evict the verifier cache (restart verifier processes or use cache controls) to remove entries created under that setting. 4) After updating, confirm normal exp/nbf behavior in a test environment. [Sources: 4098, 31978]

PatchBriefing score

3.4 / 10 · Low

Official CVSS: 5.9

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N

Why this score

The advisory lists a CVSS v3.1 base score of 5.9 (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N). That vector indicates network-accessible codepaths but exploitation requires high privileges (PR:H) and has high attack complexity (AC:H); no user interaction is required (UI:N). Confidentiality and integrity impacts are rated high, while availability impact is none. PatchWire's composite score for this advisory is 3.4, which combines the CVSS base with other factors such as the absence of public exploits and the need for privileged access. [Sources: 4098, 31978]

Affected versions

fast-jwt ≥ 0 < 6.3.0
vulnerable
≥ 6.3.0
patched

Reported fixes

A vendor fix is available in 6.3.0. If you can apply updates, upgrade fast-jwt to 6.3.0. Where upgrades are not immediately possible, avoid configuring clockTolerance as Infinity; restrict administrative configuration paths that could set that value. Because verifier cache entries created under an Infinity configuration can remain valid until eviction, clear or evict verifier cache entries (for example by restarting verifier processes or using application-specific cache controls) to remove entries created with infinite bounds. [Sources: 4098, 31978]

How this was built

2 source records were collected, matched and used to prepare the report above.

  • OSV.dev database
  • NVD (NIST) database
Unified report
fast-jwt: clockTolerance = Infinity bypasses exp/nbf and persists in verifier cache (CVE-2026-107721)
1 article · 2 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email