Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-x937-hj6v-793p | fast-jwt: Verifier cache accepts expired JWTs without iat. |
Fri, 09 Oct 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 Oct 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nearform
Nearform fast-jwt |
|
| Vendors & Products |
Nearform
Nearform fast-jwt |
Thu, 08 Oct 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.4, the fast-jwt createVerifier cache can continue accepting a previously valid, signed JWT after its exp time when caching is enabled and the token has exp but no iat. In src/verifier.js, cacheSet derives the exp cache deadline only when iat is present, so the cache falls back to cacheTTL, and a later cache hit returns the saved payload before verifyToken rechecks expiration. An attacker who can replay the same cached bearer token can extend access until the cache entry expires, but cannot forge a token through this issue. This issue is fixed in version 6.3.4. | |
| Title | fast-jwt: Verifier cache accepts expired JWTs without iat. | |
| Weaknesses | CWE-613 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-09T15:48:26.096Z
Reserved: 2026-10-08T17:21:52.975Z
Link: CVE-2026-107719
Updated: 2026-10-09T15:47:56.323Z
Status : Deferred
Published: 2026-10-08T22:17:27.913
Modified: 2026-10-09T16:17:23.457
Link: CVE-2026-107719
No data.
OpenCVE Enrichment
Updated: 2026-10-09T00:00:09Z
-
CWE-613
Insufficient Session Expiration
Github GHSA