CVE-2026-79664: Go Jwt Nil Expiresat Dereferencecve-2026-79664-go-jwt-nil-expiresat-dereference
Directly accessing `ExpiresAt.Time` on JWT claims without checking if `ExpiresAt` is nil causes a nil pointer dereference panic for tokens without an expiration (`exp`) claim. This can crash revocation and logout handlers, allowing tokens to remain valid.