HMAC Vulnerability in fast-jwt JSON Web Token Library by Nearform
CVE-2026-107724

7.4HIGH

Key Information:

Vendor

Nearform

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107724?

The fast-jwt library, vital for JSON Web Token operations, has a vulnerability where it improperly classifies serialized public JWK or JWKS JSON as HMAC secret material in version 6.2.4. This misclassification is due to the 'src/crypto.js' file which treats non-PEM strings inappropriately. If an attacker is aware of the exact serialized public-key bytes, they can exploit this flaw to create a token with arbitrary claims accepted by 'createVerifier'. To mitigate this risk, it is essential to update to version 6.3.0, which addresses this issue. Applications that utilize only PEM keys with an asymmetric algorithm allowlist are not affected.

Affected Version(s)

fast-jwt >= 6.2.4, < 6.3.0

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.