Authentication Bypass in fast-jwt Library from NearForm
CVE-2026-107720

7.4HIGH

Key Information:

Vendor

Nearform

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107720?

The fast-jwt library, which provides a fast implementation of JSON Web Tokens (JWT), contains a vulnerability that allows an attacker to bypass authentication or authorization checks. Prior to version 6.3.1, the createVerifier function in fast-jwt can erroneously accept an unsigned JWT when the key is either an empty string or null, as long as the algorithms list is non-empty. This exploit permits an attacker to submit tokens with arbitrary claims without the necessity of possessing a valid signing key. Although claim validators still execute, configurations using non-empty keys, an empty key without specified algorithms, or the asynchronous key resolver pathway do not exhibit this vulnerability. This issue has been addressed in version 6.3.1, where necessary safeguards have been implemented.

Affected Version(s)

fast-jwt < 6.3.1

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.