Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-107722: fast-jwt may accept public key as secret, allowing login bypass

CVE-2026-107722 · published 1 day ago
Summary

Versions of fast-jwt from 6.2.0 up to 6.3.0 could mistake a public RSA key for a shared secret when extra characters appear before the key header. This mistake lets an attacker create forged tokens that the system trusts, potentially bypassing authentication or authorization. Upgrade to version 6.3.0 or later, or configure the software to allow only asymmetric algorithms, to stop the issue.

What to do
  • Update GitHub Actions fast-jwt to version 6.3.0.
  • Update fast-jwt to version 6.3.0.
Affected software
Ecosystem VendorProductAffected versions
– nearform fast-jwt >= 6.2.0, < 6.3.0
npm GitHub Actions fast-jwt >= 6.2.0, <= 6.2.4
Fix: upgrade to 6.3.0
npm – fast-jwt >= 6.2.0, <= 6.2.4
Fix: upgrade to 6.3.0
Original advisory text
fast-jwt: Incomplete patch of CVE-2026-34950: Non-whitespace key-prefix re-enables RSA→HS256 algorithm confusion
fast-jwt provides fast JSON Web Token (JWT) implementation. From 6.2.0 until 6.3.0, fast-jwt can misclassify RSA public-key text as an HMAC secret when the key has non-whitespace content before its PEM header. In src/crypto.js, performDetectPublicKeyAlgorithms trims whitespace but publicKeyPemMatcher remains start-anchored, so comments, control characters, zero-width characters, or wrapper text can prevent PEM detection and reach the HMAC fallback. An attacker who knows the public key bytes can sign arbitrary HS256 claims with that public material when HS256 is inferred or allowed, resulting in authentication or authorization bypass. An asymmetric-only algorithm allowlist prevents the attack. This issue is fixed in version 6.3.0.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically (estimated)
  • Gives an attacker full control (estimated)
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-347Improper Verification of Cryptographic Signature
Timeline
Published8 Oct 2026
Updated10 Oct 2026
First seen8 Oct 2026
Sources
CVE-2026-107722 · MITRE
Track software like this
Free during beta