{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-107275", "assignerOrgId": "ce714d77-add3-4f53-aff5-83d477b104bb", "state": "PUBLISHED", "assignerShortName": "openjs", "dateReserved": "2026-10-07T15:36:05.942Z", "datePublished": "2026-10-08T11:05:40.492Z", "dateUpdated": "2026-10-08T11:05:40.492Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "ce714d77-add3-4f53-aff5-83d477b104bb", "shortName": "openjs", "dateUpdated": "2026-10-08T11:05:40.492Z" }, "descriptions": [ { "lang": "en", "value": "@fastify/jwt is a JSON Web Token plugin for the Fastify web framework. In versions before 10.2.3, a time span passed to expiresIn, notBefore, or maxAge that the plugin's parser cannot read, such as a compound span, a month unit, an ISO 8601 duration, a decimal comma, or a value with surrounding whitespace, is silently dropped instead of refused. On the signing path this produces a token with no expiration claim that never expires, and on the verification path a configured maxAge stops being enforced, so a token that should be rejected for age is accepted. The issue is fixed in @fastify/jwt 10.2.3, and users should upgrade to 10.2.3 or later. As a workaround, pass these options as a number of seconds, or verify that any time-span string parses to a finite value before relying on it.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "@fastify/jwt is a JSON Web Token plugin for the Fastify web framework. In versions before 10.2.3, a time span passed to expiresIn, notBefore, or maxAge that the plugin's parser cannot read, such as a compound span, a month unit, an ISO 8601 duration, a decimal comma, or a value with surrounding whitespace, is silently dropped instead of refused. On the signing path this produces a token with no expiration claim that never expires, and on the verification path a configured maxAge stops being enforced, so a token that should be rejected for age is accepted. The issue is fixed in @fastify/jwt 10.2.3, and users should upgrade to 10.2.3 or later. As a workaround, pass these options as a number of seconds, or verify that any time-span string parses to a finite value before relying on it." } ] } ], "affected": [ { "vendor": "@fastify/jwt", "product": "@fastify/jwt", "defaultStatus": "unaffected", "versions": [ { "versionType": "semver", "status": "affected", "version": "0", "lessThan": "10.2.3" }, { "versionType": "semver", "status": "unaffected", "version": "10.2.3" } ], "packageURL": "pkg:npm/@fastify/jwt" } ], "references": [ { "url": "https://github.com/fastify/fastify-jwt/security/advisories/GHSA-9x4w-r9p5-5h7m" }, { "url": "https://cna.openjsf.org/security-advisories.html" } ], "credits": [ { "lang": "en", "type": "reporter", "value": "kagebunsher" }, { "lang": "en", "type": "remediation developer", "value": "mcollina" }, { "lang": "en", "type": "remediation reviewer", "value": "UlisesGascon" } ], "title": "@fastify/jwt vulnerable to missing token expiration when temporal options cannot be parsed", "metrics": [ { "format": "CVSS", "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N", "baseScore": 6.8, "baseSeverity": "MEDIUM" }, "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-390", "lang": "en", "description": "CWE-390: Detection of Error Condition Without Action", "type": "CWE" } ] }, { "descriptions": [ { "cweId": "CWE-613", "lang": "en", "description": "CWE-613: Insufficient Session Expiration", "type": "CWE" } ] }, { "descriptions": [ { "cweId": "CWE-754", "lang": "en", "description": "CWE-754: Improper Check for Unusual or Exceptional Conditions", "type": "CWE" } ] } ], "x_generator": { "engine": "cve-kit 1.0.0" } } } }