Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Out-of-range NumericDate claims can throw unchecked DateTimeException during verification

Aperta
#782 1 commento 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

@ANSHUL-REAL ci sta già lavorando.

Dal 24/7/2026.

  • #790 di @ANSHUL-REAL — aperta

Valutazione

Difficoltà
3/5
Tempo stimato
1-2 giorni
Idoneità per principianti
72/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Tranquilla
Stack tecnologico
java

Direzione di ricerca

Inizia da JWTVerifier.verify(String), quindi leggi JWTParser.parsePayload(...) e PayloadDeserializer.getInstantFromSeconds(...) nei file indicati di lib/src/main/java/com/auth0/jwt. Esegui la riproduzione Maven fornita con il valore exp fuori intervallo e verifica che exp, nbf e iat non sfuggano più come DateTimeException, ma raggiungano il confine delle eccezioni della libreria per i token non validi.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

bug
Checklist
  • I have looked into the Readme and Examples, and have not found a suitable solution or answer.
  • I have looked into the API documentation and have not found a suitable solution or answer.
  • I have searched the issues and have not found a suitable solution or answer.
  • I have searched the Auth0 Community forums and have not found a suitable solution or answer.
  • I agree to the terms within the Auth0 Code of Conduct.
Description

JWTVerifier.verify(String) can throw java.time.DateTimeException when a registered NumericDate claim (exp, nbf, or iat) is a JSON number that fits in long but is outside the range supported by java.time.Instant.

The README verification example documents handling invalid tokens through JWTVerificationException:

try {
    decodedJWT = verifier.verify(token);
} catch (JWTVerificationException exception) {
    // Invalid signature/claims
}

For the out-of-range NumericDate case, the exception escapes as DateTimeException before signature verification reaches the usual invalid-token path.

The relevant code path in 4.5.2 / current master is:

  1. JWTVerifier.verify(String) constructs a JWTDecoder before verifying the decoded token.
    Reference: https://github.com/auth0/java-jwt/blob/695fd2bea64b8466b872a9d0c2e7019fee7ac86f/lib/src/main/java/com/auth0/jwt/JWTVerifier.java#L450-L452
  2. JWTParser.parsePayload(...) catches IOException from Jackson parsing.
    Reference: https://github.com/auth0/java-jwt/blob/695fd2bea64b8466b872a9d0c2e7019fee7ac86f/lib/src/main/java/com/auth0/jwt/impl/JWTParser.java#L39-L46
  3. PayloadDeserializer.getInstantFromSeconds(...) checks canConvertToLong(), then calls Instant.ofEpochSecond(node.asLong()).
    Reference: https://github.com/auth0/java-jwt/blob/695fd2bea64b8466b872a9d0c2e7019fee7ac86f/lib/src/main/java/com/auth0/jwt/impl/PayloadDeserializer.java#L72-L81

9223372036854775807 passes the long conversion check but is outside the valid Instant epoch-second range. The result is an unchecked DateTimeException instead of a JWTVerificationException / JWTDecodeException.

Expected behavior:

Out-of-range registered NumericDate claims should be rejected through the library's normal invalid-token exception boundary.

Actual behavior:

JWTVerifier.verify(String) throws java.time.DateTimeException.

Reproduction

Create the following files in an empty directory.

First create the source directory:

mkdir -p src/main/java/repro

pom.xml:

<project xmlns="http://maven.apache.org/POM/4.0.0"
         xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
         xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 https://maven.apache.org/xsd/maven-4.0.0.xsd">
  <modelVersion>4.0.0</modelVersion>

  <groupId>repro</groupId>
  <artifactId>java-jwt-numericdate-repro</artifactId>
  <version>1.0.0</version>

  <properties>
    <maven.compiler.source>11</maven.compiler.source>
    <maven.compiler.target>11</maven.compiler.target>
  </properties>

  <dependencies>
    <dependency>
      <groupId>com.auth0</groupId>
      <artifactId>java-jwt</artifactId>
      <version>4.5.2</version>
    </dependency>
  </dependencies>

  <build>
    <plugins>
      <plugin>
        <groupId>org.codehaus.mojo</groupId>
        <artifactId>exec-maven-plugin</artifactId>
        <version>3.5.0</version>
      </plugin>
    </plugins>
  </build>
</project>

src/main/java/repro/NumericDateRepro.java:

package repro;

import com.auth0.jwt.JWT;
import com.auth0.jwt.algorithms.Algorithm;
import com.auth0.jwt.exceptions.JWTVerificationException;

import java.nio.charset.StandardCharsets;
import java.time.DateTimeException;
import java.util.Base64;

public final class NumericDateRepro {
    public static void main(String[] args) {
        String payload = "{\"exp\":9223372036854775807}";
        String token = base64Url("{\"alg\":\"HS256\",\"typ\":\"JWT\"}") + "."
                + base64Url(payload) + ".invalidsig";

        try {
            JWT.require(Algorithm.HMAC256("secret")).build().verify(token);
            System.out.println("unexpected: token accepted");
            System.exit(2);
        } catch (JWTVerificationException expectedBoundary) {
            System.out.println("expected boundary: " + expectedBoundary.getClass().getName());
            System.exit(0);
        } catch (DateTimeException escaped) {
            System.out.println("reproduced unchecked exception: " + escaped.getClass().getName());
            System.out.println("payload=" + payload);
            System.exit(1);
        }
    }

    private static String base64Url(String value) {
        return Base64.getUrlEncoder()
                .withoutPadding()
                .encodeToString(value.getBytes(StandardCharsets.UTF_8));
    }
}

Run:

mvn -q compile exec:java -Dexec.mainClass=repro.NumericDateRepro

Observed result:

reproduced unchecked exception: java.time.DateTimeException
payload={"exp":9223372036854775807}

Success / failure oracle:

  • Current behavior: the command prints reproduced unchecked exception: java.time.DateTimeException and exits with status 1.
  • Expected fixed behavior: the command prints expected boundary: ...JWTVerificationException... or another library-controlled invalid-token exception and exits with status 0.

The same behavior can be exercised with nbf or iat instead of exp.

Additional context

No response

java-jwt version

4.5.2

Java version

Java 11

Lingua principale
Java
Stelle
6.2k
Fork
947
Merge medio
52m
PR unite (30g)
3

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di auth0/java-jwt

Tutte le issue di auth0/java-jwt

Issue simili

Altre issue su Java

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.