fast-jwt has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was October 2026 with 6. The median CVSS is 7.4 (high), with 1 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-347 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.4
- Publish → KEV
- —
- Last 90 days
- 6 prev 0
Weakness classes
Products
- fast-jwt 6
Worst active — by depth score
CVE-2026-107722Critical· 9.8fast-jwt provides fast JSON Web Token (JWT) implementation54CVE-2026-107723High· 8.1fast-jwt provides fast JSON Web Token (JWT) implementation45CVE-2026-107724High· 7.4fast-jwt provides fast JSON Web Token (JWT) implementation41CVE-2026-107720High· 7.4fast-jwt provides fast JSON Web Token (JWT) implementation41CVE-2026-107721Medium· 5.9fast-jwt provides fast JSON Web Token (JWT) implementation32
fast-jwt vulnerabilities
CVEs affecting fast-jwt, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2026-107724High· 7.4fast-jwt provides fast JSON Web Token (JWT) implementation
fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.2.4, fast-jwt can classify raw serialized public JWK or JWKS JSON as an HMAC secret because src/crypto.js performDetectPublicKeyAlgorithms treats non-PEM strings as symmetr…
CVE-2026-107723High· 8.1fast-jwt provides fast JSON Web Token (JWT) implementation
fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.0, fast-jwt createVerifier accepts a validly signed JWT whose payload is a JSON array because src/decoder.js checks that the payload is an object but does not rejec…
CVE-2026-107721Medium· 5.9fast-jwt provides fast JSON Web Token (JWT) implementation
fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.0, fast-jwt createVerifier accepts Infinity for clockTolerance because its option validation checks type and negativity but not finiteness. In validateClaimDateValu…
CVE-2026-107722Critical· 9.8fast-jwt provides fast JSON Web Token (JWT) implementation
fast-jwt provides fast JSON Web Token (JWT) implementation. From 6.2.0 until 6.3.0, fast-jwt can misclassify RSA public-key text as an HMAC secret when the key has non-whitespace content before its PEM header. In src/crypto.js, performDe…
CVE-2026-107720High· 7.4fast-jwt provides fast JSON Web Token (JWT) implementation
fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.1, fast-jwt createVerifier accepts an unsigned JWT when key is an empty string or null and algorithms is a non-empty allowlist. Falsy synchronous keys bypass prepar…
CVE-2026-107719Medium· 4.2fast-jwt provides fast JSON Web Token (JWT) implementation
fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.4, the fast-jwt createVerifier cache can continue accepting a previously valid, signed JWT after its exp time when caching is enabled and the token has exp but no i…