fast-jwt 提供了高效的 JSON Web Token (JWT) 实现。在版本 6.2.4 中,fast-jwt 可能将原始序列化的公开 JWK 或 JWKS JSON 误识别为 HMAC 密钥,这是因为 src/crypto.js 中的 performDetectPublicKeyAlgorithms 函数将非 PEM 格式的字符串视为对称密钥材料。如果 HS256 算法被显式允许或被推断使用,攻击者可以利用已知的公开密钥序列化字节作为 HMAC 密钥,创建包含任意声明(claims)的令牌,而该令牌会被
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107722 | 9.8 CRITICAL | fast-jwt: Incomplete patch of CVE-2026-34950: Non-whitespace key-prefix re-enables RSA→HS2 |
| CVE-2026-107723 | 8.1 HIGH | fast-jwt : Silent claim-validator bypass when JWT payload is a JSON array |
| CVE-2026-107720 | 7.4 HIGH | fast-jwt: createVerifier accepts unsigned JWTs when key is '' or null and algorithms is ex |
| CVE-2026-107721 | 5.9 MEDIUM | fast-jwt clockTolerance: Infinity silently bypasses both exp and nbf validation (and persi |
| CVE-2026-107719 | 4.2 MEDIUM | fast-jwt: Verifier cache accepts expired JWTs without iat. |
No comments yet