Vendor
The fast-jwt library (<= 6.3.0) fails to verify JWT signatures when the 'key' configuration is falsy and 'algorithms' are explicitly defined, allowing unauthenticated attackers to forge arbitrary claims.