HIGH SEVERITYCONFIRMED
JWT expiry check skipped when exp=None (falsy check)
Package
fastmcp
Version
2.14.5
Verified
2026-03-28
Description
In `fastmcp/server/auth/jwt_issuer.py:215`, the expiry check uses `if exp and exp < time.time()`. When `exp=None`, Python evaluates `None` as falsy and short-circuits — the expiry check is never performed. Tokens without an expiry claim are unconditionally accepted.
Reproduction
import time
exp = None
if exp and exp < time.time(): # evaluates to: if None = False
raise Exception('expired')
# Token accepted — expiry not enforced