HIGH SEVERITYCONFIRMED
JWT expiry bypassed when exp=0 (Unix epoch is falsy)
Package
fastmcp
Version
2.14.5
Verified
2026-03-28
Description
The same falsy check `if exp and ...` in fastmcp's JWT verifier means a token with `exp=0` (January 1, 1970 — long expired) passes validation. Integer `0` is falsy in Python, so a 55-year-old token is accepted as valid.
Reproduction
import time
exp = 0 # Unix epoch — long expired
if exp and exp < time.time(): # if 0 = False
raise Exception('expired')
# 1970 token accepted