PT-2026-108251 · Npm · Fast-Jwt
CVE-2026-107722
·
Published
2026-10-08
·
Updated
2026-10-08
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
fast-jwt versions 6.2.0 through 6.2.x
Description
fast-jwt can misclassify an RSA public key as an HMAC secret if the key contains non-whitespace content (such as control characters, zero-width characters, comments, or wrapper text) before its PEM header. In the
performDetectPublicKeyAlgorithms() function within src/crypto.js, the software trims whitespace but uses a start-anchored regular expression to detect the PEM header. Consequently, any non-whitespace leading byte causes the detection to fail, leading the system to fall back to HMAC verification using the RSA public key as the shared secret. An attacker who knows the public key can sign arbitrary claims using the HS256 algorithm, potentially resulting in authentication or authorization bypass. This issue is particularly critical when an asymmetric-only algorithm allowlist is not used.Recommendations
Update fast-jwt to version 6.3.0.
As a temporary mitigation, use an asymmetric-only algorithm allowlist (e.g.,
algorithms: ['RS256']) when creating the verifier to prevent the HMAC fallback.Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fast-Jwt