PT-2026-108252 · Npm · Fast-Jwt
CVE-2026-107723
·
Published
2026-10-08
·
Updated
2026-10-08
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
fast-jwt versions prior to 6.3.0
Description
The
createVerifier function in fast-jwt fails to properly validate that the JSON Web Token (JWT) payload is a JSON object. Because JavaScript treats arrays as objects, a validly signed JWT with a JSON array as its payload can bypass the decoder's check in src/decoder.js. Consequently, the claim validator loop in src/verifier.js finds no named properties (such as exp, nbf, iss, aud, sub, jti, or nonce) and silently skips all configured security checks. This allows an attacker who can produce or influence a signed token to bypass expiry, issuer, audience, subject, revocation, and replay protections. The requiredClaims option can block this behavior, but it is an opt-in feature.Recommendations
Update fast-jwt to version 6.3.0.
As a temporary mitigation, enable the
requiredClaims option to block tokens with missing claims.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fast-Jwt