Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107721— fast-jwt clockTolerance: Infinity silently bypasses both exp and nbf validation (and persists in the verifier cache)

Quick assessment

Affected
nearform fast-jwt
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

fast-jwt 提供了快速高效的 JSON Web Token (JWT) 实现。在版本 6.3.0 之前,fast-jwt 的 createVerifier 函数接受 clockTolerance 参数为 Infinity,因为其选项验证仅检查类型和是否为负数,而未验证数值是否为有限值(finiteness)。在 validateClaimDateValue 函数中,无穷大且为正的修改值会导致 exp(过期时间)和 nbf(生效前时间)的比较始终通过,从而允许已过期的或尚未激活的令牌被接受。此外,验证器缓存也会

CVSS 5.9 · Medium

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107721

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
fast-jwt clockTolerance: Infinity silently bypasses both exp and nbf validation (and persists in the verifier cache)
Source: CVE Program / CVE List V5
Vulnerability Description
fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.0, fast-jwt createVerifier accepts Infinity for clockTolerance because its option validation checks type and negativity but not finiteness. In validateClaimDateValue, infinite positive and negative modifiers make exp and nbf comparisons always pass, allowing expired or not-yet-active tokens to be accepted. The verifier cache also derives infinite bounds, so entries created under this configuration can remain valid until eviction. Exploitation requires an application administrator or equivalent configuration path to set clockTolerance to Infinity. This issue is fixed in version 6.3.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
不充分的会话过期机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
nearform fast-jwt < 6.3.0 -

II. Public POCs for CVE-2026-107721

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107721

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-107721 (1)

Vendor Advisories for CVE-2026-107721 (1)

Vendor Pages for CVE-2026-107721 (1)

Same Patch Batch · nearform · 2026-10-08 · 6 CVEs total

CVE-2026-107722 9.8 CRITICAL fast-jwt: Incomplete patch of CVE-2026-34950: Non-whitespace key-prefix re-enables RSA→HS2
CVE-2026-107723 8.1 HIGH fast-jwt : Silent claim-validator bypass when JWT payload is a JSON array
CVE-2026-107720 7.4 HIGH fast-jwt: createVerifier accepts unsigned JWTs when key is '' or null and algorithms is ex
CVE-2026-107724 7.4 HIGH fast-jwt treats raw public JWK JSON as an HMAC secret, enabling HS256 token forgery
CVE-2026-107719 4.2 MEDIUM fast-jwt: Verifier cache accepts expired JWTs without iat.

IV. Related Vulnerabilities

V. Comments for CVE-2026-107721

No comments yet


Leave a comment