CVE-2026-107275

LOWCVSS 6.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

@fastify/jwt is a JSON Web Token plugin for the Fastify web framework. In versions before 10.2.3, a time span passed to expiresIn, notBefore, or maxAge that the plugin's parser cannot read, such as a compound span, a month unit, an ISO 8601 duration, a decimal comma, or a value with surrounding whitespace, is silently dropped instead of refused. On the signing path this produces a token with no expiration claim that never expires, and on the verification path a configured maxAge stops being enforced, so a token that should be rejected for age is accepted. The issue is fixed in @fastify/jwt 10.2.3, and users should upgrade to 10.2.3 or later. As a workaround, pass these options as a number of seconds, or verify that any time-span string parses to a finite value before relying on it.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-390CWE-613CWE-754

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-08: 110-08
Referenced assets1 URL
By indicator
Full discourse1 post
  • Ulises Gascón@kom_256

    🚨 Medium-severity security fix in @fastify/jwt@10.2.3 just released! Patches CVE-2026-107275: @fastify/jwt vulnerable to missing token expiration when temporal options cannot be parsed https://github.com/fastify/fastify-jwt/security/advisories/GHSA-9x4w-r9p5-5h7m

    0000034
    5.5K followersView on X

Explore more