Authentication Bypass Vulnerability in Fast JWT by NearForm
CVE-2026-107722

9.8CRITICAL

Key Information:

Vendor

Nearform

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107722?

The fast-jwt library, which provides an implementation for JSON Web Tokens, is susceptible to authentication bypass due to an issue in its handling of RSA public keys. Specifically, from versions 6.2.0 to 6.3.0, the library can erroneously classify RSA public-key text as an HMAC secret if there are non-whitespace characters before the PEM header. This misclassification occurs because while whitespace is trimmed, the pattern matcher for public keys can misinterpret additional characters leading to an improper fallback to HMAC. If an attacker is aware of the public key, they can exploit this vulnerability to sign arbitrary HS256 claims, bypassing authentication or authorization checks if HS256 is permitted. The issue can be mitigated by allowing only asymmetric algorithms, and it has been resolved in version 6.3.0.

Affected Version(s)

fast-jwt >= 6.2.0, < 6.3.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.