SCA: security update for fast-jwt (GHSA-687g-22h4-j4w4)

medium Tenable Cloud Security Plugin ID 473944

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.0, fast-jwt createVerifier
accepts Infinity for clockTolerance because its option validation checks type and negativity but not
finiteness. In validateClaimDateValue, infinite positive and negative modifiers make exp and nbf
comparisons always pass, allowing expired or not-yet-active tokens to be accepted. The verifier cache also
derives infinite bounds, so entries created under this configuration can remain valid until eviction.
Exploitation requires an application administrator or equivalent configuration path to set clockTolerance
to Infinity. This issue is fixed in version 6.3.0. (CVE-2026-107721)

Solution

Update the fast-jwt library and its related packages to version 6.3.0 or later.

See Also

https://github.com/advisories/GHSA-687g-22h4-j4w4

Plugin Details

Severity: Medium

ID: 473944

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 10/9/2026

Updated: 10/9/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.46

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 6.2

Temporal Score: 4.6

Vector: CVSS2#AV:N/AC:H/Au:M/C:C/I:C/A:N

CVSS Score Source: CVE-2026-107721

CVSS v3

Risk Factor: Medium

Base Score: 5.9

Temporal Score: 5.2

Vector: CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/8/2026

Vulnerability Publication Date: 10/8/2026

Reference Information

CVE: CVE-2026-107721