Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

fast-jwt — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in fast-jwt, with AI-generated Chinese analysis, references, and POCs.

Vendor: nearform

CVE ID Title CVSS Severity Published
CVE-2026-107724 fast-jwt treats raw public JWK JSON as an HMAC secret, enabling HS256 token forgery CWE-347 7.4 High 2026-10-08
CVE-2026-107723 fast-jwt : Silent claim-validator bypass when JWT payload is a JSON array CWE-1287 8.1 High 2026-10-08
CVE-2026-107722 fast-jwt: Incomplete patch of CVE-2026-34950: Non-whitespace key-prefix re-enables RSA→HS256 algorithm confusion CWE-347 9.8 Critical 2026-10-08
CVE-2026-107721 fast-jwt clockTolerance: Infinity silently bypasses both exp and nbf validation (and persists in the verifier cache) CWE-613 5.9 Medium 2026-10-08
CVE-2026-107720 fast-jwt: createVerifier accepts unsigned JWTs when key is '' or null and algorithms is explicitly set CWE-20 7.4 High 2026-10-08
CVE-2026-107719 fast-jwt: Verifier cache accepts expired JWTs without iat. CWE-613 4.2 Medium 2026-10-08
CVE-2026-44351 fast-jwt: Empty HMAC secret accepted via async key resolver - JWT auth bypass CWE-287 9.1 Critical 2026-05-13
CVE-2026-35041 ReDoS in fast-jwt when using RegExp in allowed* leading to CPU exhaustion during token verification CWE-1333 4.2 Medium 2026-04-09
CVE-2026-35040 fast-jwt: Stateful RegExp (/g or /y) causes non-deterministic allowed-claim validation (logical DoS) CWE-697 5.3 Medium 2026-04-09
CVE-2026-35042 fast-jwt accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation) CWE-345 7.5 High 2026-04-06
CVE-2026-35039 fast-jwt Affected by Cache Confusion via cacheKeyBuilder Collisions Can Return Claims From a Different Token (Identity/Authorization Mixup) CWE-345 9.1 Critical 2026-04-06
CVE-2026-34950 fast-jwt has an incomplete fix for CVE-2023-48223: JWT Algorithm Confusion via Whitespace-Prefixed RSA Public Key CWE-327 9.1 Critical 2026-04-06
CVE-2025-30144 Fast-JWT Improperly Validates iss Claims CWE-345 6.5 Medium 2025-03-19
CVE-2023-48223 fast-jwt JWT Algorithm Confusion CWE-20 5.9 Medium 2023-11-20

All 14 known CVE vulnerabilities affecting fast-jwt with full Chinese analysis, references, and POCs where available.