{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3anearformfast-jwt/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:nearform:fast-jwt:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-107720"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["fast-jwt (\u003c= 6.3.0)"],"_cs_severities":["high"],"_cs_tags":["authentication-bypass","jwt-vulnerability","software-supply-chain"],"_cs_type":"advisory","_cs_vendors":["NearForm"],"content_html":"\u003cp\u003eThe fast-jwt library, version 6.3.0 and earlier, contains an authentication bypass vulnerability (CVE-2026-107720) in the \u003ccode\u003ecreateVerifier\u003c/code\u003e function. The vulnerability occurs due to incomplete signature verification logic when the secret \u003ccode\u003ekey\u003c/code\u003e provided is either an empty string or \u003ccode\u003enull\u003c/code\u003e. If an application is configured with an explicit \u003ccode\u003ealgorithms\u003c/code\u003e allowlist - a security practice - and the environment fails to provide a valid secret (e.g., an unset environment variable), the library skips the cryptographic signature check entirely.\u003c/p\u003e\n\u003cp\u003eThis bypass allows an attacker to construct a JWT with arbitrary payloads and an empty signature, which the library will accept as valid. Because signature validation is bypassed, any payload data - such as user roles or administrative identifiers - is accepted by the application logic as trusted. This effectively grants an attacker full authentication or authorization bypass if they can present a JWT to the service.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies an application utilizing the \u003ccode\u003efast-jwt\u003c/code\u003e library for authentication.\u003c/li\u003e\n\u003cli\u003eAttacker confirms the application is misconfigured due to a missing or empty secret key environment variable.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a custom JWT header with a valid algorithm (e.g., \u0026quot;HS256\u0026quot;) and a malicious payload.\u003c/li\u003e\n\u003cli\u003eAttacker sets the JWT signature portion to empty (trailing dot).\u003c/li\u003e\n\u003cli\u003eAttacker transmits the crafted, unsigned JWT to the target application endpoint.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003ecreateVerifier\u003c/code\u003e logic detects the explicit \u003ccode\u003ealgorithms\u003c/code\u003e setting and, due to the falsy key, bypasses the signature verification call.\u003c/li\u003e\n\u003cli\u003eThe application processes the forged token, trusting the attacker-controlled claims (e.g., \u003ccode\u003eadmin: true\u003c/code\u003e).\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a full authentication and authorization bypass. Attackers can forge arbitrary claims within the JWT, potentially gaining unauthorized access to privileged user accounts or administrative functions. The impact is significant for any service relying on JWTs for session management that has unintentionally initialized with an empty secret key.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for development and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ccode\u003efast-jwt\u003c/code\u003e to a version that addresses CVE-2026-107720 once available.\u003c/li\u003e\n\u003cli\u003eImplement a check to ensure secret keys are not null or empty strings before initializing \u003ccode\u003ecreateVerifier\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eValidate that environment variables used as JWT secrets are properly populated during application startup.\u003c/li\u003e\n\u003cli\u003ePatch CVE-2026-107720 by hardening the \u003ccode\u003ecreateVerifier\u003c/code\u003e logic to fail closed if the key is falsy regardless of the \u003ccode\u003ealgorithms\u003c/code\u003e configuration.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-09T07:58:42Z","date_published":"2026-10-09T07:58:42Z","id":"https://feed.craftedsignal.io/briefs/2026-10-fast-jwt-auth-bypass/","summary":"The fast-jwt library (\u003c= 6.3.0) fails to verify JWT signatures when the 'key' configuration is falsy and 'algorithms' are explicitly defined, allowing unauthenticated attackers to forge arbitrary claims.","title":"Authentication Bypass in fast-jwt via Unsigned JWT Processing","url":"https://feed.craftedsignal.io/briefs/2026-10-fast-jwt-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:nearform:fast-Jwt:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}