Vulnerability in fast-jwt JSON Web Token Implementation by NearForm
CVE-2026-107723

8.1HIGH

Key Information:

Vendor

Nearform

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107723?

The fast-jwt library, used for JSON Web Token (JWT) generation and verification, has a flaw in its createVerifier function that allows for improper validation of JWT payloads. Specifically, prior to version 6.3.0, the library accepted validly signed JWTs containing a JSON array as a payload, due to a check that only validated objects. This vulnerability leads to the absence of necessary checks for claims such as expiry, issuer, audience, subject, and others, potentially allowing attackers to bypass these critical protections if they can create or influence a signed token. While the optional requiredClaims can mitigate this issue by enforcing claim checks, it is imperative to upgrade to version 6.3.0 or later to ensure full protection against such vulnerabilities.

Affected Version(s)

fast-jwt < 6.3.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.