CVE-2026-107724High· 7.4▾ Twilightfast-jwt provides fast JSON Web Token (JWT) implementation. In 6.2.4, fast-jwt can classify raw serialized public JWK or JWKS JSON as an HMAC secret because src/crypto.js performDetectPublicKeyAlgorithms treats non-PEM strings as symmetr…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.2.4, fast-jwt can classify raw serialized public JWK or JWKS JSON as an HMAC secret because src/crypto.js performDetectPublicKeyAlgorithms treats non-PEM strings as symmetric key material. If HS256 is explicitly allowed or inferred, an attacker who knows the exact serialized public-key bytes can use those bytes as an HMAC key and create a token containing arbitrary claims that createVerifier accepts. Serialization ordering or whitespace differences can prevent exploitation, and applications using supported PEM keys with an asymmetric-only algorithm allowlist are not affected. This issue is fixed in version 6.3.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
fast-jwt = 6.2.4Patched in:
fast-jwt 6.3.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-107722Critical· 9.8fast-jwt provides fast JSON Web Token (JWT) implementation
CVE-2026-107721Medium· 5.9fast-jwt provides fast JSON Web Token (JWT) implementation
CVE-2026-107723High· 8.1fast-jwt provides fast JSON Web Token (JWT) implementation
CVE-2026-107720High· 7.4fast-jwt provides fast JSON Web Token (JWT) implementation
CVE-2026-107719Medium· 4.2fast-jwt provides fast JSON Web Token (JWT) implementation
CVE-2025-12295Medium· 6.6A weakness has been identified in D-Link DAP-2695 2.00RC13