Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8wpc-h4q6-8fxv | fast-jwt: createVerifier accepts unsigned JWTs when key is '' or null and algorithms is explicitly set |
Thu, 08 Oct 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.1, fast-jwt createVerifier accepts an unsigned JWT when key is an empty string or null and algorithms is a non-empty allowlist. Falsy synchronous keys bypass prepareKeyOrSecret, allowedAlgorithms remains active, hasKey is false, and the empty signature avoids the verifySignature gate. An attacker can therefore submit a token containing arbitrary claims without possessing a signing key, resulting in authentication or authorization bypass. Claim validators still run, and non-empty keys, an empty key without algorithms, and the async key resolver path do not have this behavior. This issue is fixed in version 6.3.1. | |
| Title | fast-jwt: createVerifier accepts unsigned JWTs when key is '' or null and algorithms is explicitly set | |
| Weaknesses | CWE-20 CWE-347 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-08T21:44:06.843Z
Reserved: 2026-10-08T17:21:52.975Z
Link: CVE-2026-107720
No data.
Status : Deferred
Published: 2026-10-08T22:17:28.090
Modified: 2026-10-08T22:17:28.227
Link: CVE-2026-107720
No data.
OpenCVE Enrichment
No data.
Github GHSA