fast-jwt 提供了高性能的 JSON Web Token (JWT) 实现。在 6.3.4 版本之前,当启用了缓存功能且 JWT 包含 (过期时间)字段但不包含 (签发时间)字段时, 的 缓存可能在 JWT 已过期后仍继续接受并验证该先前有效的已签名 JWT。 在 中, 仅在 存在时才推导缓存过期截止时间;否则,缓存会回退使用 作为有效期。因此,后续缓存命中会直接返回之前缓存的载荷(payload),而无需再次通过 重新验证过期时间。攻击者若能重复使用(重放)同一个已被缓存的 Bearer 令牌,则可在缓存条
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107722 | 9.8 CRITICAL | fast-jwt: Incomplete patch of CVE-2026-34950: Non-whitespace key-prefix re-enables RSA→HS2 |
| CVE-2026-107723 | 8.1 HIGH | fast-jwt : Silent claim-validator bypass when JWT payload is a JSON array |
| CVE-2026-107720 | 7.4 HIGH | fast-jwt: createVerifier accepts unsigned JWTs when key is '' or null and algorithms is ex |
| CVE-2026-107724 | 7.4 HIGH | fast-jwt treats raw public JWK JSON as an HMAC secret, enabling HS256 token forgery |
| CVE-2026-107721 | 5.9 MEDIUM | fast-jwt clockTolerance: Infinity silently bypasses both exp and nbf validation (and persi |
No comments yet