LOW SEVERITYCONFIRMED
loads(token, max_age=0) does NOT expire tokens
Package
itsdangerous
Version
2.2.0
Verified
2026-03-28
Description
itsdangerous uses `age > max_age` (strict greater-than) for its expiry check. A just-signed token has `age ~= 0`. Since `0 > 0` is `False`, the token is not expired when `max_age=0`. Any caller using `max_age=0` to mean 'must be zero-age' will find all tokens are accepted.
Reproduction
from itsdangerous import URLSafeTimedSerializer
ts = URLSafeTimedSerializer('secret')
token = ts.dumps({'user': 'test'})
result = ts.loads(token, max_age=0)
# Returns: {'user': 'test'} — NOT expired