CVE-2026-107722
Deferred Deferred - Pending Action

JWT Authentication Bypass in fast-jwt

Vulnerability report for CVE-2026-107722, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

fast-jwt provides fast JSON Web Token (JWT) implementation. From 6.2.0 until 6.3.0, fast-jwt can misclassify RSA public-key text as an HMAC secret when the key has non-whitespace content before its PEM header. In src/crypto.js, performDetectPublicKeyAlgorithms trims whitespace but publicKeyPemMatcher remains start-anchored, so comments, control characters, zero-width characters, or wrapper text can prevent PEM detection and reach the HMAC fallback. An attacker who knows the public key bytes can sign arbitrary HS256 claims with that public material when HS256 is inferred or allowed, resulting in authentication or authorization bypass. An asymmetric-only algorithm allowlist prevents the attack. This issue is fixed in version 6.3.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
nearform fast-jwt >= 6.2.0, < 6.3.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-347 The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

fast-jwt versions 6.2.0 to 6.3.0 incorrectly classify RSA public keys as HMAC secrets if the key contains non-whitespace text before the PEM header. This happens because the public key detection fails to recognize the key format, leading the system to use HMAC instead of RSA for signing. Attackers can exploit this by signing arbitrary HS256 tokens with the public key material, bypassing authentication or authorization checks.

Impact Analysis

If you use fast-jwt versions between 6.2.0 and 6.3.0, an attacker could forge JWT tokens to impersonate users or escalate privileges. This could allow unauthorized access to sensitive data or actions protected by the JWT authentication system. The impact is high as it affects confidentiality, integrity, and availability of the system.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR's data protection principles and HIPAA's security requirements. Non-compliance may result in legal penalties, reputational damage, and loss of trust. Organizations must ensure JWT implementations are secure to meet these regulatory standards.

Mitigation Strategies

Upgrade fast-jwt to version 6.3.0 or later to address the vulnerability. Ensure only asymmetric algorithms are allowed in JWT verification to prevent HMAC fallback abuse.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107722. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart