Security: nearform/fast-jwt
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
createVerifier accepts unsigned JWTs when key is '' or null and algorithms is explicitly setGHSA-8wpc-h4q6-8fxv published
Jul 30, 2026 by SociableSteveHigh -
fast-jwt 6.2.4 treats raw public JWK JSON as an HMAC secret, enabling HS256 token forgeryGHSA-g3jj-5cmm-3hxx published
Jul 28, 2026 by SociableSteveHigh -
clockTolerance: Infinity silently bypasses both exp and nbf validation (and persists in the verifier cache)GHSA-687g-22h4-j4w4 published
Jul 28, 2026 by lv10Moderate -
Silent claim-validator bypass when JWT payload is a JSON arrayGHSA-5hjw-83fp-phq9 published
Jul 28, 2026 by lv10High -
Empty HMAC secret accepted via async key resolver - JWT auth bypassGHSA-gmvf-9v4p-v8jc published
Apr 29, 2026 by SociableSteveCritical -
Incomplete patch of CVE-2026-34950: Non-whitespace key-prefix re-enables RSA→HS256 algorithm confusion in fast-jwt 6.2.xGHSA-ww5h-9m49-7xx4 published
Jul 28, 2026 by lv10Critical -
Incomplete fix for CVE-2023-48223: JWT Algorithm Confusion via Whitespace-Prefixed RSA Public KeyGHSA-mvf2-f6gm-w987 published
Apr 2, 2026 by antoatta85Critical -
Security Report: fast-jwt accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)GHSA-hm7r-c7qw-ghp6 published
Apr 2, 2026 by antoatta85High -
Cache Confusion via cacheKeyBuilder Collisions Can Return Claims From a Different Token (Identity/Authorization Mixup)GHSA-rp9m-7r4c-75qg published
Apr 2, 2026 by antoatta85Critical -
Addendum: Stateful RegExp (/g or /y) causes non-deterministic allowed-claim validation (logical DoS)GHSA-3j8v-cgw4-2g6q published
Apr 9, 2026 by antoatta85Moderate
Learn more about advisories related to nearform/fast-jwt in the GitHub Advisory Database