PT-2026-108252 · Npm · Fast-Jwt

CVE-2026-107723

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions fast-jwt versions prior to 6.3.0
Description The createVerifier function in fast-jwt fails to properly validate that the JSON Web Token (JWT) payload is a JSON object. Because JavaScript treats arrays as objects, a validly signed JWT with a JSON array as its payload can bypass the decoder's check in src/decoder.js. Consequently, the claim validator loop in src/verifier.js finds no named properties (such as exp, nbf, iss, aud, sub, jti, or nonce) and silently skips all configured security checks. This allows an attacker who can produce or influence a signed token to bypass expiry, issuer, audience, subject, revocation, and replay protections. The requiredClaims option can block this behavior, but it is an opt-in feature.
Recommendations Update fast-jwt to version 6.3.0. As a temporary mitigation, enable the requiredClaims option to block tokens with missing claims.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107723
GHSA-5HJW-83FP-PHQ9

Affected Products

Fast-Jwt