PT-2026-108253 · Npm · Fast-Jwt

CVE-2026-107724

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions fast-jwt version 6.2.4
Description An issue exists where raw serialized public JSON Web Key (JWK) or JSON Web Key Set (JWKS) JSON is incorrectly classified as an HMAC secret. This occurs because the performDetectPublicKeyAlgorithms() function in src/crypto.js treats any non-empty string that does not match PEM formats as symmetric key material. If the HS256 algorithm is explicitly allowed or automatically inferred, an attacker who knows the exact serialized public-key bytes can use those bytes as an HMAC key to create forged tokens with arbitrary claims. This can lead to authentication or authorization bypass, including privilege escalation. The issue is triggered when the verifier is configured with a raw JWK/JWKS string and does not restrict algorithms to asymmetric-only families.
Recommendations Update fast-jwt to version 6.3.0. As a temporary mitigation, restrict the algorithms allowlist to asymmetric-only families (e.g., RS256) and avoid using raw JWK/JWKS JSON as the verifier key.

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107724
GHSA-G3JJ-5CMM-3HXX

Affected Products

Fast-Jwt