HIGH SEVERITYCONFIRMED

JWT expiry bypassed when exp=0 (Unix epoch is falsy)

Package
fastmcp
Version
2.14.5
Verified
2026-03-28

Description

The same falsy check `if exp and ...` in fastmcp's JWT verifier means a token with `exp=0` (January 1, 1970 — long expired) passes validation. Integer `0` is falsy in Python, so a 55-year-old token is accepted as valid.

Reproduction

import time
exp = 0  # Unix epoch — long expired
if exp and exp < time.time():   # if 0 = False
    raise Exception('expired')
# 1970 token accepted
← All bugsScan your code →