---
id: CVE-2026-107275
title: '@fastify/jwt is a JSON Web Token plugin for the Fastify web framework'
summary: >-
  @fastify/jwt is a JSON Web Token plugin for the Fastify web framework. In
  versions before 10.2.3, a time span passed to expiresIn, notBefore, or maxAge
  that the plugin's parser cannot read, such as a compound span, a month unit,
  an ISO 8…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-390
  - CWE-613
  - CWE-754
vendor: '@fastify/jwt'
product: '@fastify/jwt'
affected:
  - '@fastify/jwt < 10.2.3'
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T12:17:14.553'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107275'
references:
  - url: 'https://cna.openjsf.org/security-advisories.html'
    label: ce714d77-add3-4f53-aff5-83d477b104bb
  - url: >-
      https://github.com/fastify/fastify-jwt/security/advisories/GHSA-9x4w-r9p5-5h7m
    label: ce714d77-add3-4f53-aff5-83d477b104bb
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-08T11:31:27.692Z'
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-08T14:21:14.347462Z'
---

## Overview

@fastify/jwt is a JSON Web Token plugin for the Fastify web framework. In versions before 10.2.3, a time span passed to expiresIn, notBefore, or maxAge that the plugin's parser cannot read, such as a compound span, a month unit, an ISO 8601 duration, a decimal comma, or a value with surrounding whitespace, is silently dropped instead of refused. On the signing path this produces a token with no expiration claim that never expires, and on the verification path a configured maxAge stops being enforced, so a token that should be rejected for age is accepted. The issue is fixed in @fastify/jwt 10.2.3, and users should upgrade to 10.2.3 or later. As a workaround, pass these options as a number of seconds, or verify that any time-span string parses to a finite value before relying on it.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
