PT-2026-108249 · Npm · Fast-Jwt

CVE-2026-107720

·

Published

2026-10-08

·

Updated

2026-10-09

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions fast-jwt versions prior to 6.3.1
Description In the createVerifier() function, the software fails to properly validate the signing key when it is provided as an empty string or null while a non-empty allowlist is specified in the algorithms parameter. This occurs because falsy synchronous keys bypass the prepareKeyOrSecret() function, and the internal logic incorrectly permits tokens with an empty signature to skip the verifySignature() gate. Consequently, an attacker can submit a JSON Web Token (JWT) containing arbitrary claims without a valid signing key, leading to a complete authentication or authorization bypass. This issue is specifically triggered when the key variable is falsy and the algorithms allowlist is active, which is a common scenario when secrets are loaded from unset environment variables.
Recommendations Update fast-jwt to version 6.3.1. As a temporary mitigation, ensure that the key parameter passed to createVerifier() is neither null nor an empty string before initializing the verifier.

Fix

RCE

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107720
GHSA-8WPC-H4Q6-8FXV

Affected Products

Fast-Jwt