Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8wpc-h4q6-8fxv | fast-jwt: createVerifier accepts unsigned JWTs when key is '' or null and algorithms is explicitly set |
Fri, 09 Oct 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nearform
Nearform fast-jwt |
|
| Vendors & Products |
Nearform
Nearform fast-jwt |
Thu, 08 Oct 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.1, fast-jwt createVerifier accepts an unsigned JWT when key is an empty string or null and algorithms is a non-empty allowlist. Falsy synchronous keys bypass prepareKeyOrSecret, allowedAlgorithms remains active, hasKey is false, and the empty signature avoids the verifySignature gate. An attacker can therefore submit a token containing arbitrary claims without possessing a signing key, resulting in authentication or authorization bypass. Claim validators still run, and non-empty keys, an empty key without algorithms, and the async key resolver path do not have this behavior. This issue is fixed in version 6.3.1. | |
| Title | fast-jwt: createVerifier accepts unsigned JWTs when key is '' or null and algorithms is explicitly set | |
| Weaknesses | CWE-20 CWE-347 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-08T21:44:06.843Z
Reserved: 2026-10-08T17:21:52.975Z
Link: CVE-2026-107720
No data.
Status : Deferred
Published: 2026-10-08T22:17:28.090
Modified: 2026-10-08T22:17:28.227
Link: CVE-2026-107720
No data.
OpenCVE Enrichment
Updated: 2026-10-09T00:15:13Z
Github GHSA