Authentication Bypass in fast-jwt Library from NearForm
CVE-2026-107720
What is CVE-2026-107720?
The fast-jwt library, which provides a fast implementation of JSON Web Tokens (JWT), contains a vulnerability that allows an attacker to bypass authentication or authorization checks. Prior to version 6.3.1, the createVerifier function in fast-jwt can erroneously accept an unsigned JWT when the key is either an empty string or null, as long as the algorithms list is non-empty. This exploit permits an attacker to submit tokens with arbitrary claims without the necessity of possessing a valid signing key. Although claim validators still execute, configurations using non-empty keys, an empty key without specified algorithms, or the asynchronous key resolver pathway do not exhibit this vulnerability. This issue has been addressed in version 6.3.1, where necessary safeguards have been implemented.
Affected Version(s)
fast-jwt < 6.3.1
