PT-2026-108249 · Npm · Fast-Jwt
CVE-2026-107720
·
Published
2026-10-08
·
Updated
2026-10-09
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
fast-jwt versions prior to 6.3.1
Description
In the
createVerifier() function, the software fails to properly validate the signing key when it is provided as an empty string or null while a non-empty allowlist is specified in the algorithms parameter. This occurs because falsy synchronous keys bypass the prepareKeyOrSecret() function, and the internal logic incorrectly permits tokens with an empty signature to skip the verifySignature() gate. Consequently, an attacker can submit a JSON Web Token (JWT) containing arbitrary claims without a valid signing key, leading to a complete authentication or authorization bypass. This issue is specifically triggered when the key variable is falsy and the algorithms allowlist is active, which is a common scenario when secrets are loaded from unset environment variables.Recommendations
Update fast-jwt to version 6.3.1.
As a temporary mitigation, ensure that the
key parameter passed to createVerifier() is neither null nor an empty string before initializing the verifier.Fix
RCE
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fast-Jwt