Description
fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.0, fast-jwt createVerifier accepts a validly signed JWT whose payload is a JSON array because src/decoder.js checks that the payload is an object but does not reject arrays. The claim validator loop then finds no named exp, nbf, iss, aud, sub, jti, or nonce properties and silently skips those configured checks, returning the array as a successfully verified payload. An attacker who can produce or influence a validly signed token may bypass expiry, issuer, audience, subject, revocation, and replay protections. The opt-in requiredClaims option can block missing claims, and signature verification itself is not bypassed. This issue is fixed in version 6.3.0.
Published: 2026-10-08
Score: 8.1 High
EPSS: n/a
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No solution or workaround provided in the CVE record.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-5hjw-83fp-phq9 fast-jwt : Silent claim-validator bypass when JWT payload is a JSON array
History

Fri, 09 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Nearform
Nearform fast-jwt
Vendors & Products Nearform
Nearform fast-jwt

Thu, 08 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
Description fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.0, fast-jwt createVerifier accepts a validly signed JWT whose payload is a JSON array because src/decoder.js checks that the payload is an object but does not reject arrays. The claim validator loop then finds no named exp, nbf, iss, aud, sub, jti, or nonce properties and silently skips those configured checks, returning the array as a successfully verified payload. An attacker who can produce or influence a validly signed token may bypass expiry, issuer, audience, subject, revocation, and replay protections. The opt-in requiredClaims option can block missing claims, and signature verification itself is not bypassed. This issue is fixed in version 6.3.0.
Title fast-jwt : Silent claim-validator bypass when JWT payload is a JSON array
Weaknesses CWE-1287
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Nearform Fast-jwt
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T21:51:22.183Z

Reserved: 2026-10-08T17:21:52.976Z

Link: CVE-2026-107723

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-08T22:17:28.623

Modified: 2026-10-08T22:17:28.757

Link: CVE-2026-107723

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T00:00:09Z

Weaknesses