Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107719— fast-jwt: Verifier cache accepts expired JWTs without iat.

Quick assessment

Affected
nearform fast-jwt
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

fast-jwt 提供了高性能的 JSON Web Token (JWT) 实现。在 6.3.4 版本之前,当启用了缓存功能且 JWT 包含 (过期时间)字段但不包含 (签发时间)字段时, 的 缓存可能在 JWT 已过期后仍继续接受并验证该先前有效的已签名 JWT。 在 中, 仅在 存在时才推导缓存过期截止时间;否则,缓存会回退使用 作为有效期。因此,后续缓存命中会直接返回之前缓存的载荷(payload),而无需再次通过 重新验证过期时间。攻击者若能重复使用(重放)同一个已被缓存的 Bearer 令牌,则可在缓存条

CVSS 4.2 · Medium

Possible ATT&CK Techniques 1 AI

T1133 · External Remote Services
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107719

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
fast-jwt: Verifier cache accepts expired JWTs without iat.
Source: CVE Program / CVE List V5
Vulnerability Description
fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.4, the fast-jwt createVerifier cache can continue accepting a previously valid, signed JWT after its exp time when caching is enabled and the token has exp but no iat. In src/verifier.js, cacheSet derives the exp cache deadline only when iat is present, so the cache falls back to cacheTTL, and a later cache hit returns the saved payload before verifyToken rechecks expiration. An attacker who can replay the same cached bearer token can extend access until the cache entry expires, but cannot forge a token through this issue. This issue is fixed in version 6.3.4.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
不充分的会话过期机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
nearform fast-jwt < 6.3.4 -

II. Public POCs for CVE-2026-107719

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107719

请登录查看更多情报信息。

Other References for CVE-2026-107719 (3)

Same Patch Batch · nearform · 2026-10-08 · 6 CVEs total

CVE-2026-107722 9.8 CRITICAL fast-jwt: Incomplete patch of CVE-2026-34950: Non-whitespace key-prefix re-enables RSA→HS2
CVE-2026-107723 8.1 HIGH fast-jwt : Silent claim-validator bypass when JWT payload is a JSON array
CVE-2026-107720 7.4 HIGH fast-jwt: createVerifier accepts unsigned JWTs when key is '' or null and algorithms is ex
CVE-2026-107724 7.4 HIGH fast-jwt treats raw public JWK JSON as an HMAC secret, enabling HS256 token forgery
CVE-2026-107721 5.9 MEDIUM fast-jwt clockTolerance: Infinity silently bypasses both exp and nbf validation (and persi

IV. Related Vulnerabilities

V. Comments for CVE-2026-107719

No comments yet


Leave a comment