---
id: CVE-2026-107724
title: fast-jwt provides fast JSON Web Token (JWT) implementation
summary: >-
  fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.2.4, fast-jwt
  can classify raw serialized public JWK or JWKS JSON as an HMAC secret because
  src/crypto.js performDetectPublicKeyAlgorithms treats non-PEM strings as
  symmetr…
severity: high
cvss: 7.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-347
vendor: fast-jwt
product: fast-jwt
affected:
  - fast-jwt = 6.2.4
patched:
  - fast-jwt 6.3.0
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:17:28.930'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107724'
references:
  - url: >-
      https://github.com/nearform/fast-jwt/commit/10f9591349199ed2ab9fa1748ce92cdca697f6cf
    label: security-advisories@github.com
  - url: 'https://github.com/nearform/fast-jwt/pull/636'
    label: security-advisories@github.com
  - url: 'https://github.com/nearform/fast-jwt/releases/tag/v6.3.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/nearform/fast-jwt/security/advisories/GHSA-g3jj-5cmm-3hxx
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-g3jj-5cmm-3hxx'
tags:
  - nvd
  - ghsa
  - npm
aliases:
  - GHSA-g3jj-5cmm-3hxx
ecosystem: npm
ingestedAt: '2026-10-08T22:11:53.874Z'
---

## Overview

fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.2.4, fast-jwt can classify raw serialized public JWK or JWKS JSON as an HMAC secret because src/crypto.js performDetectPublicKeyAlgorithms treats non-PEM strings as symmetric key material. If HS256 is explicitly allowed or inferred, an attacker who knows the exact serialized public-key bytes can use those bytes as an HMAC key and create a token containing arbitrary claims that createVerifier accepts. Serialization ordering or whitespace differences can prevent exploitation, and applications using supported PEM keys with an asymmetric-only algorithm allowlist are not affected. This issue is fixed in version 6.3.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-107724)

Affected packages:

- `fast-jwt = 6.2.4`

Patched in:

- `fast-jwt 6.3.0`

Source: https://github.com/advisories/GHSA-g3jj-5cmm-3hxx
