Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.7 Node.js & npm GHSA-5hjw-83fp-phq9 CVE-2026-107723

fast-jwt silent claim-validator bypass — CVE-2026-107723

fast-jwt's verifier accepted JWTs whose payload is a JSON array instead of an object, causing configured claim checks (exp, aud, iss, etc.) to be skipped and allowing bypass of expiry and other protections. Fixed in 6.3.0. (CVE-2026-107723 / GHSA-5hjw-83fp-phq9)

Synthesized by AI from 2 sources · updated 1 hour ago

AI summary

CVE-2026-107723 (GHSA-5hjw-83fp-phq9) affects the fast-jwt npm package. A flaw in the verifier allowed validly signed tokens whose payload is a JSON array to bypass claim checks. The issue is fixed in 6.3.0. Source: OSV and NVD.

What happened

fast-jwt's createVerifier accepted a validly signed JWT whose payload was a JSON array because the decoder checked that the payload was an object but did not reject arrays. The claim validator loop then found no named exp, nbf, iss, aud, sub, jti, or nonce properties and silently skipped those configured checks, returning the array as a successfully verified payload. Signature verification itself was not bypassed. (Sources: OSV, NVD)

Technical cause

The decoder's payload-type check permitted arrays; the claim-validation loop assumes a payload object and only looks up named claim properties. When the payload is an array, those named properties are absent and the validator skips configured checks rather than rejecting the token. The opt-in requiredClaims option can block missing claims but was not enforced by default. (Sources: OSV, NVD)

Why it matters

An attacker who can produce or influence a validly signed token can cause the verifier to accept a token whose payload is an array and thereby bypass expiry, issuer, audience, subject, revocation, and replay protections that rely on named claims. The vulnerability has CVSS 3.1 base score 8.1 (CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). (Sources: OSV, NVD)

Who is affected

Applications and services using the fast-jwt npm package with the affected code path are affected. The token must be validly signed; an attacker needs the ability to produce or influence a validly signed JWT to exploit the issue. (Sources: OSV, NVD)

Discovery and timeline

The OSV advisory and NVD entry for this issue were published on 2026-10-08. The vulnerability was assigned CVE-2026-107723 and GHSA-5hjw-83fp-phq9. (Sources: OSV, NVD)

Affected versions

The advisory lists the affected range as introduced at "0" and fixed at "6.3.0"; any releases prior to the fixed release are in the affected range per the advisory. (Source: OSV)

Fixes and mitigation

The issue is fixed in 6.3.0. The opt-in requiredClaims option can block missing claims and mitigate this issue if enabled. Signature verification is not bypassed by the bug. If you cannot immediately upgrade, enable requiredClaims (where feasible) and validate that accepted tokens have payloads that are JSON objects. (Sources: OSV, NVD)

Recommended action

Upgrade fast-jwt to 6.3.0. Review token-handling code and ensure tokens accepted by your application have object payloads and include required claims. If immediate upgrade is not possible, enable the package's requiredClaims option to enforce required claims. Monitor vendor and NVD advisories for further updates. (Sources: OSV, NVD)

PatchBriefing score

4.7 / 10 · Medium

Official CVSS: 8.1

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Why this score

The advisory reports a CVSS 3.1 base score of 8.1 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N), reflecting high impact to confidentiality and integrity when an attacker can present a validly signed token. PatchWire's composite score for this advisory is 4.7; contributing factors include the CVSS base score and the fact that no user interaction is required. Known-exploited and public-exploit flags are false in the supplied facts. (Sources: OSV, NVD)

Affected versions

fast-jwt ≥ 0 < 6.3.0
vulnerable
≥ 6.3.0
patched

Reported fixes

The issue is fixed in 6.3.0. The opt-in requiredClaims option can block missing claims and mitigate this issue if enabled. Signature verification is not bypassed by the bug. If you cannot immediately upgrade, enable requiredClaims (where feasible) and validate that accepted tokens have payloads that are JSON objects. (Sources: OSV, NVD)

How this was built

2 source records were collected, matched and used to prepare the report above.

  • OSV.dev database
  • NVD (NIST) database
Unified report
fast-jwt silent claim-validator bypass — CVE-2026-107723
1 article · 2 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email