<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:nearform:fast-Jwt:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3anearformfast-jwt/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 09 Oct 2026 07:58:42 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3anearformfast-jwt/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass in fast-jwt via Unsigned JWT Processing</title><link>https://feed.craftedsignal.io/briefs/2026-10-fast-jwt-auth-bypass/</link><pubDate>Fri, 09 Oct 2026 07:58:42 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-fast-jwt-auth-bypass/</guid><description>The fast-jwt library (&lt;= 6.3.0) fails to verify JWT signatures when the 'key' configuration is falsy and 'algorithms' are explicitly defined, allowing unauthenticated attackers to forge arbitrary claims.</description><content:encoded><![CDATA[<p>The fast-jwt library, version 6.3.0 and earlier, contains an authentication bypass vulnerability (CVE-2026-107720) in the <code>createVerifier</code> function. The vulnerability occurs due to incomplete signature verification logic when the secret <code>key</code> provided is either an empty string or <code>null</code>. If an application is configured with an explicit <code>algorithms</code> allowlist - a security practice - and the environment fails to provide a valid secret (e.g., an unset environment variable), the library skips the cryptographic signature check entirely.</p>
<p>This bypass allows an attacker to construct a JWT with arbitrary payloads and an empty signature, which the library will accept as valid. Because signature validation is bypassed, any payload data - such as user roles or administrative identifiers - is accepted by the application logic as trusted. This effectively grants an attacker full authentication or authorization bypass if they can present a JWT to the service.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies an application utilizing the <code>fast-jwt</code> library for authentication.</li>
<li>Attacker confirms the application is misconfigured due to a missing or empty secret key environment variable.</li>
<li>Attacker crafts a custom JWT header with a valid algorithm (e.g., &quot;HS256&quot;) and a malicious payload.</li>
<li>Attacker sets the JWT signature portion to empty (trailing dot).</li>
<li>Attacker transmits the crafted, unsigned JWT to the target application endpoint.</li>
<li>The <code>createVerifier</code> logic detects the explicit <code>algorithms</code> setting and, due to the falsy key, bypasses the signature verification call.</li>
<li>The application processes the forged token, trusting the attacker-controlled claims (e.g., <code>admin: true</code>).</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in a full authentication and authorization bypass. Attackers can forge arbitrary claims within the JWT, potentially gaining unauthorized access to privileged user accounts or administrative functions. The impact is significant for any service relying on JWTs for session management that has unintentionally initialized with an empty secret key.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for development and security teams:</p>
<ul>
<li>Upgrade <code>fast-jwt</code> to a version that addresses CVE-2026-107720 once available.</li>
<li>Implement a check to ensure secret keys are not null or empty strings before initializing <code>createVerifier</code>.</li>
<li>Validate that environment variables used as JWT secrets are properly populated during application startup.</li>
<li>Patch CVE-2026-107720 by hardening the <code>createVerifier</code> logic to fail closed if the key is falsy regardless of the <code>algorithms</code> configuration.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>authentication-bypass</category><category>jwt-vulnerability</category><category>software-supply-chain</category></item></channel></rss>