CVE-2026-107724
- EPSS 0.22%
- Veröffentlicht 08.10.2026 21:53:01
- Zuletzt bearbeitet 09.10.2026 16:17:23
fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.2.4, fast-jwt can classify raw serialized public JWK or JWKS JSON as an HMAC secret because src/crypto.js performDetectPublicKeyAlgorithms treats non-PEM strings as symmetric key materi...
CVE-2026-107723
- EPSS 0.36%
- Veröffentlicht 08.10.2026 21:51:22
- Zuletzt bearbeitet 08.10.2026 22:17:28
fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.0, fast-jwt createVerifier accepts a validly signed JWT whose payload is a JSON array because src/decoder.js checks that the payload is an object but does not reject arrays. The...
CVE-2026-107722
- EPSS 0.27%
- Veröffentlicht 08.10.2026 21:49:55
- Zuletzt bearbeitet 08.10.2026 22:17:28
fast-jwt provides fast JSON Web Token (JWT) implementation. From 6.2.0 until 6.3.0, fast-jwt can misclassify RSA public-key text as an HMAC secret when the key has non-whitespace content before its PEM header. In src/crypto.js, performDetectPublicKey...
CVE-2026-107721
- EPSS 0.33%
- Veröffentlicht 08.10.2026 21:45:57
- Zuletzt bearbeitet 09.10.2026 16:17:23
fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.0, fast-jwt createVerifier accepts Infinity for clockTolerance because its option validation checks type and negativity but not finiteness. In validateClaimDateValue, infinite p...
CVE-2026-107720
- EPSS 0.26%
- Veröffentlicht 08.10.2026 21:44:06
- Zuletzt bearbeitet 09.10.2026 15:17:08
fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.1, fast-jwt createVerifier accepts an unsigned JWT when key is an empty string or null and algorithms is a non-empty allowlist. Falsy synchronous keys bypass prepareKeyOrSecret,...
CVE-2026-107719
- EPSS 0.23%
- Veröffentlicht 08.10.2026 21:41:55
- Zuletzt bearbeitet 09.10.2026 16:17:23
fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.4, the fast-jwt createVerifier cache can continue accepting a previously valid, signed JWT after its exp time when caching is enabled and the token has exp but no iat. In src/ve...
CVE-2026-44351
- EPSS 0.24%
- Veröffentlicht 13.05.2026 19:12:33
- Zuletzt bearbeitet 14.05.2026 19:16:37
fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.4, a critical authentication-bypass vulnerability in fast-jwt's async key-resolver flow allows any unauthenticated attacker to forge arbitrary JWTs that are accepted as authenti...
CVE-2026-35040
- EPSS 0.38%
- Veröffentlicht 09.04.2026 16:16:27
- Zuletzt bearbeitet 17.04.2026 20:10:05
fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.1, using certain modifiers on RegExp objects in the allowedAud, allowedIss, allowedSub, allowedJti, or allowedNonce options in verify functions can cause certain unintended beha...
CVE-2026-35041
- EPSS 0.26%
- Veröffentlicht 09.04.2026 16:16:27
- Zuletzt bearbeitet 14.04.2026 20:15:13
fast-jwt provides fast JSON Web Token (JWT) implementation. From 5.0.0 to 6.2.0, a denial-of-service condition exists in fast-jwt when the allowedAud verification option is configured using a regular expression. Because the aud claim is attacker-cont...
CVE-2026-35042
- EPSS 0.16%
- Veröffentlicht 06.04.2026 17:02:12
- Zuletzt bearbeitet 10.04.2026 18:35:35
fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, fast-jwt does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that fast-jwt doe...