fast-jwt 提供了快速实现 JSON Web Token(JWT)的库。在版本 6.3.0 之前,fast-jwt 的 函数会接受负载(payload)为 JSON 数组且签名有效的 JWT。这是因为在 中,代码仅检查负载是否为对象(object),但未拒绝数组(array)。由于 JSON 数组不包含名为 、 、 、 、 、 或 的声明(claims),声明验证循环找不到这些属性,从而静默跳过所有相关的配置验证,并直接将数组作为验证成功的负载返回。 攻击者若能构造或影响一个签名有效的令牌,即可绕过令牌过期时
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107722 | 9.8 CRITICAL | fast-jwt: Incomplete patch of CVE-2026-34950: Non-whitespace key-prefix re-enables RSA→HS2 |
| CVE-2026-107720 | 7.4 HIGH | fast-jwt: createVerifier accepts unsigned JWTs when key is '' or null and algorithms is ex |
| CVE-2026-107724 | 7.4 HIGH | fast-jwt treats raw public JWK JSON as an HMAC secret, enabling HS256 token forgery |
| CVE-2026-107721 | 5.9 MEDIUM | fast-jwt clockTolerance: Infinity silently bypasses both exp and nbf validation (and persi |
| CVE-2026-107719 | 4.2 MEDIUM | fast-jwt: Verifier cache accepts expired JWTs without iat. |
No comments yet