MEDIUM
@fastify/jwt
CVE published 2026-10-08
CVE-2026-107275
The @fastify/jwt package, a JSON Web Token plugin for the Fastify web framework, has a vulnerability in versions before 10.2.3. When a time span is passed to expiresIn, notBefore, or maxAge that the plugin's parser cannot read, such as a compound span, a month unit, an ISO 8601 duration, a decimal comma, or a value with surrounding whitespace, it is silently dropped. This results in a token with no expira [truncated]