fast-jwt 提供了一个快速实现的 JSON Web Token(JWT)库。在 6.3.1 版本之前,当密钥为空字符串或 null,且 algorithms 参数为非空白名单时,createVerifier 方法会接受未签名的 JWT。此时,虚假(falsy)同步密钥会绕过 prepareKeyOrSecret 处理流程,allowedAlgorithms 仍保持启用状态,hasKey 为 false,且空签名会绕过 verifySignature 验证网关。因此,攻击者可以提交包含任意声明(claims)的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107722 | 9.8 CRITICAL | fast-jwt: Incomplete patch of CVE-2026-34950: Non-whitespace key-prefix re-enables RSA→HS2 |
| CVE-2026-107723 | 8.1 HIGH | fast-jwt : Silent claim-validator bypass when JWT payload is a JSON array |
| CVE-2026-107724 | 7.4 HIGH | fast-jwt treats raw public JWK JSON as an HMAC secret, enabling HS256 token forgery |
| CVE-2026-107721 | 5.9 MEDIUM | fast-jwt clockTolerance: Infinity silently bypasses both exp and nbf validation (and persi |
| CVE-2026-107719 | 4.2 MEDIUM | fast-jwt: Verifier cache accepts expired JWTs without iat. |
No comments yet