HIGH SEVERITYCONFIRMED

JWT expiry check skipped when exp=None (falsy check)

Package
fastmcp
Version
2.14.5
Verified
2026-03-28

Description

In `fastmcp/server/auth/jwt_issuer.py:215`, the expiry check uses `if exp and exp < time.time()`. When `exp=None`, Python evaluates `None` as falsy and short-circuits — the expiry check is never performed. Tokens without an expiry claim are unconditionally accepted.

Reproduction

import time
exp = None
if exp and exp < time.time():   # evaluates to: if None = False
    raise Exception('expired')
# Token accepted — expiry not enforced
← All bugsScan your code →