CVE-2026-107720: CWE-20: Improper Input Validation in nearform fast-jwt
Description
fast-jwt before version 6.3.1 has an improper input validation vulnerability where the createVerifier function accepts unsigned JWTs under certain conditions, allowing authentication or authorization bypass. This occurs when the signing key is an empty string or null and a non-empty allowlist of algorithms is used. The issue is fixed in version 6.3.1.
CVSS v3.1
Score 7.4high
Affected software
nearform
fast-jwt
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The fast-jwt library versions prior to 6.3.1 contain a vulnerability in the createVerifier function. When the key parameter is an empty string or null and the algorithms parameter is a non-empty allowlist, the verifier accepts unsigned JWTs. This happens because falsy synchronous keys bypass the prepareKeyOrSecret function, leaving allowedAlgorithms active while hasKey is false, allowing an empty signature to bypass the verifySignature check. Consequently, an attacker can submit tokens with arbitrary claims without possessing a valid signing key, resulting in authentication or authorization bypass. Claim validators still execute, and this behavior does not occur with non-empty keys, empty keys without algorithms, or when using the asynchronous key resolver path. The vulnerability is addressed in fast-jwt version 6.3.1.
Potential Impact
An attacker can bypass authentication or authorization by submitting unsigned JWTs with arbitrary claims when the vulnerable conditions are met. This can lead to unauthorized access or privilege escalation in systems relying on fast-jwt for JWT verification. The vulnerability does not affect scenarios where keys are non-empty, algorithms are empty, or asynchronous key resolution is used.
Mitigation Recommendations
Upgrade fast-jwt to version 6.3.1 or later, where this vulnerability is fixed. No other mitigation is required as the fix addresses the root cause.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-10-08T17:21:52.975Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac8135e2cdf04f6563b0cec
Added to database: 10/08/2026, 22:04:14 UTC
Last enriched: 10/08/2026, 22:18:23 UTC
Last updated: 10/08/2026, 22:19:11 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.