{"id":"CVE-2026-107724","title":"fast-jwt provides fast JSON Web Token (JWT) implementation","summary":"fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.2.4, fast-jwt can classify raw serialized public JWK or JWKS JSON as an HMAC secret because src/crypto.js performDetectPublicKeyAlgorithms treats non-PEM strings as symmetr…","severity":"high","cvss":7.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-347"],"vendor":"fast-jwt","product":"fast-jwt","affected":["fast-jwt = 6.2.4"],"patched":["fast-jwt 6.3.0"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:17:28.930","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107724","references":[{"url":"https://github.com/nearform/fast-jwt/commit/10f9591349199ed2ab9fa1748ce92cdca697f6cf","label":"security-advisories@github.com"},{"url":"https://github.com/nearform/fast-jwt/pull/636","label":"security-advisories@github.com"},{"url":"https://github.com/nearform/fast-jwt/releases/tag/v6.3.0","label":"security-advisories@github.com"},{"url":"https://github.com/nearform/fast-jwt/security/advisories/GHSA-g3jj-5cmm-3hxx","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-g3jj-5cmm-3hxx"}],"tags":["nvd","ghsa","npm"],"aliases":["GHSA-g3jj-5cmm-3hxx"],"ecosystem":"npm","ingestedAt":"2026-10-08T22:11:53.874Z","slug":"CVE-2026-107724","body":"## Overview\n\nfast-jwt provides fast JSON Web Token (JWT) implementation. In 6.2.4, fast-jwt can classify raw serialized public JWK or JWKS JSON as an HMAC secret because src/crypto.js performDetectPublicKeyAlgorithms treats non-PEM strings as symmetric key material. If HS256 is explicitly allowed or inferred, an attacker who knows the exact serialized public-key bytes can use those bytes as an HMAC key and create a token containing arbitrary claims that createVerifier accepts. Serialization ordering or whitespace differences can prevent exploitation, and applications using supported PEM keys with an asymmetric-only algorithm allowlist are not affected. This issue is fixed in version 6.3.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-107724)\n\nAffected packages:\n\n- `fast-jwt = 6.2.4`\n\nPatched in:\n\n- `fast-jwt 6.3.0`\n\nSource: https://github.com/advisories/GHSA-g3jj-5cmm-3hxx","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":40.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}