MEDIUM SEVERITYCONFIRMED
Fernet.decrypt(ttl=0) accepts same-second tokens — off-by-one in TTL check
Package
cryptography
Version
46.0.5
Verified
2026-03-28
Description
Fernet's TTL check uses strict less-than: `if timestamp + ttl < current_time`. When `ttl=0` and a token is created and decrypted within the same second, `T + 0 < T` is False, so the token is accepted. Any application using `ttl=0` to mean 'zero-lifetime' or 'reject all' will silently accept same-second tokens. This is the same off-by-one pattern as the itsdangerous `max_age=0` vulnerability.
Reproduction
from cryptography.fernet import Fernet
key = Fernet.generate_key()
f = Fernet(key)
token = f.encrypt(b'secret')
result = f.decrypt(token, ttl=0)
# Returns: b'secret' — same-second token accepted, no exception
# Expected: InvalidToken raised (zero-TTL should expire immediately)