PatchSiren

@fastify/jwt CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM @fastify/jwt CVE published 2026-10-08

CVE-2026-107275

The @fastify/jwt package, a JSON Web Token plugin for the Fastify web framework, has a vulnerability in versions before 10.2.3. When a time span is passed to expiresIn, notBefore, or maxAge that the plugin's parser cannot read, such as a compound span, a month unit, an ISO 8601 duration, a decimal comma, or a value with surrounding whitespace, it is silently dropped. This results in a token with no expira [truncated]