CVE-2026-107722: CWE-347: Improper Verification of Cryptographic Signature in nearform fast-jwt
Description
fast-jwt versions from 6.2.0 up to but not including 6.3.0 contain a vulnerability where RSA public keys with non-whitespace content before the PEM header are misclassified as HMAC secrets. This misclassification allows an attacker who knows the public key bytes to forge HS256 signatures, potentially bypassing authentication or authorization. The issue is fixed in version 6.3.0.
CVSS v3.1
Score 9.8critical
Affected software
nearform
fast-jwt
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
fast-jwt, a JSON Web Token implementation, improperly verifies cryptographic signatures when RSA public keys contain non-whitespace characters before the PEM header. The detection logic trims whitespace but does not account for other characters, causing the system to fallback to HMAC verification incorrectly. This allows an attacker with knowledge of the public key bytes to sign arbitrary HS256 claims, resulting in authentication or authorization bypass. The vulnerability affects versions >=6.2.0 and <6.3.0 and is resolved in version 6.3.0 by correcting the key detection logic and allowing an asymmetric-only algorithm allowlist to prevent the attack.
Potential Impact
An attacker who knows the RSA public key bytes can exploit this vulnerability to forge HS256 signatures, leading to authentication and authorization bypass. This compromises the integrity and trustworthiness of JWT tokens generated or verified by affected versions of fast-jwt, potentially allowing unauthorized access to protected resources.
Mitigation Recommendations
Upgrade fast-jwt to version 6.3.0 or later, where this vulnerability is fixed. Additionally, configuring an asymmetric-only algorithm allowlist can prevent this attack. No other mitigation is required once the upgrade is applied.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-10-08T17:21:52.975Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac8135e2cdf04f6563b0cee
Added to database: 10/08/2026, 22:04:14 UTC
Last enriched: 10/08/2026, 22:18:19 UTC
Last updated: 10/08/2026, 22:19:11 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.