Sceawere
Vulnerability Detail
CVE-2026-107275UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
@fastify/jwt Improper Time Validation
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.8
- Creation Date
- 2h ago
- Vendor
- @fastify/jwt
- Product
- @fastify/jwt
- Attack Type
- CWE-390: Detection of Error Condition Without Action
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
@fastify/jwt is a JSON Web Token plugin for the Fastify web framework. In versions before 10.2.3, a time span passed to expiresIn, notBefore, or maxAge that the plugin's parser cannot read, such as a compound span, a month unit, an ISO 8601 duration, a decimal comma, or a value with surrounding whitespace, is silently dropped instead of refused. On the signing path this produces a token with no expiration claim that never expires, and on the verification path a configured maxAge stops being enforced, so a token that should be rejected for age is accepted. The issue is fixed in @fastify/jwt 10.2.3, and users should upgrade to 10.2.3 or later. As a workaround, pass these options as a number of seconds, or verify that any time-span string parses to a finite value before relying on it.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.8",
"pubDate": "2026-10-08T12:17:14.553Z",
"pubdate": "2026-10-08T12:17:14.553Z",
"executiveSummary": "The vulnerability identified in @fastify/jwt (versions prior to 10.2.3) involves an improper validation mechanism for time-span configuration options, specifically expiresIn, notBefore, and maxAge.\nWhen provided with non-standard or complex time-span string formats—such as compound units, ISO 8601 durations, decimal commas, or strings containing surrounding whitespace—the plugin's parser fails to interpret the input correctly.\nInstead of rejecting the invalid input or raising an exception, the system silently ignores these directives.\nThis flaw results in critical security regressions: tokens generated for signing are emitted without expiration claims (permitting indefinite validity), and verification routines cease enforcing maxAge constraints, allowing expired tokens to bypass authentication checks.\nThe vulnerability exposes applications to session hijacking, replay attacks, and long-term unauthorized access.\nAttackers do not require specific elevated privileges to exploit this; they only need the application to be configured with the vulnerable string-based time-span settings.\nThe risk is severe as it undermines the fundamental security guarantees of token-based authentication systems implemented within the Fastify framework.",
"technicalDetails": "The root cause of this vulnerability lies in the sanitization and parsing logic of the time-span configuration values within the @fastify/jwt plugin. The internal parser relies on a strict interpretation of time-span strings and fails to implement an error-handling path for strings that do not conform to expected formats.\nUnder normal operations, configuration parameters like 'expiresIn' or 'maxAge' are expected to be either an integer (representing seconds) or a recognizable string format. When the plugin encounters unparseable input (e.g., '1 month', 'P1D' (ISO 8601), or '10.5 seconds'), the underlying parsing function returns 'undefined' rather than throwing an error.\nIn the token signing flow, if the 'expiresIn' parameter is provided as an unparseable string, the plugin fails to inject the 'exp' (expiration) claim into the JWT payload. Because the library silently proceeds, it generates a JWT that lacks an expiration timestamp, effectively granting the token infinite longevity. An attacker who is issued such a token retains access indefinitely until the signing secret is rotated or invalidated, significantly increasing the window of opportunity for post-exploitation activities.\nIn the token verification flow, the 'maxAge' option is intended to perform a temporal check on the 'iat' (issued at) claim. If the 'maxAge' configuration is provided as an unparseable string, the parser defaults to a state where the temporal check is effectively disabled. Consequently, the verification logic fails to reject tokens that should have been invalidated due to exceeding their intended lifespan. An attacker can use this behavior to perform replay attacks by reusing intercepted, legitimately expired tokens, as the plugin will treat them as current.\nThe attack flow involves: (1) Identifying an application using @fastify/jwt < 10.2.3 that utilizes string-based duration configurations. (2) If the server-side configuration uses a non-standard string format, the token logic enters an insecure state. (3) If the vulnerability affects the signing path, the attacker gains a long-lived credential. (4) If it affects the verification path, the attacker presents an expired token, which the system erroneously validates. This issue impacts all network-exposed endpoints relying on @fastify/jwt for session management."
}