Medium · 4.7 Node.js & npm GHSA-5hjw-83fp-phq9 CVE-2026-107723
fast-jwt silent claim-validator bypass — CVE-2026-107723
fast-jwt's verifier accepted JWTs whose payload is a JSON array instead of an object, causing configured claim checks (exp, aud, iss, etc.) to be skipped and allowing bypass of expiry and other protections. Fixed in 6.3.0. (CVE-2026-107723 / GHSA-5hjw-83fp-phq9)
AI summary
CVE-2026-107723 (GHSA-5hjw-83fp-phq9) affects the fast-jwt npm package. A flaw in the verifier allowed validly signed tokens whose payload is a JSON array to bypass claim checks. The issue is fixed in 6.3.0. Source: OSV and NVD.
What happened
fast-jwt's createVerifier accepted a validly signed JWT whose payload was a JSON array because the decoder checked that the payload was an object but did not reject arrays. The claim validator loop then found no named exp, nbf, iss, aud, sub, jti, or nonce properties and silently skipped those configured checks, returning the array as a successfully verified payload. Signature verification itself was not bypassed. (Sources: OSV, NVD)
Technical cause
The decoder's payload-type check permitted arrays; the claim-validation loop assumes a payload object and only looks up named claim properties. When the payload is an array, those named properties are absent and the validator skips configured checks rather than rejecting the token. The opt-in requiredClaims option can block missing claims but was not enforced by default. (Sources: OSV, NVD)
Why it matters
An attacker who can produce or influence a validly signed token can cause the verifier to accept a token whose payload is an array and thereby bypass expiry, issuer, audience, subject, revocation, and replay protections that rely on named claims. The vulnerability has CVSS 3.1 base score 8.1 (CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). (Sources: OSV, NVD)
Who is affected
Applications and services using the fast-jwt npm package with the affected code path are affected. The token must be validly signed; an attacker needs the ability to produce or influence a validly signed JWT to exploit the issue. (Sources: OSV, NVD)
Discovery and timeline
The OSV advisory and NVD entry for this issue were published on 2026-10-08. The vulnerability was assigned CVE-2026-107723 and GHSA-5hjw-83fp-phq9. (Sources: OSV, NVD)
Affected versions
The advisory lists the affected range as introduced at "0" and fixed at "6.3.0"; any releases prior to the fixed release are in the affected range per the advisory. (Source: OSV)
Fixes and mitigation
The issue is fixed in 6.3.0. The opt-in requiredClaims option can block missing claims and mitigate this issue if enabled. Signature verification is not bypassed by the bug. If you cannot immediately upgrade, enable requiredClaims (where feasible) and validate that accepted tokens have payloads that are JSON objects. (Sources: OSV, NVD)
Recommended action
Upgrade fast-jwt to 6.3.0. Review token-handling code and ensure tokens accepted by your application have object payloads and include required claims. If immediate upgrade is not possible, enable the package's requiredClaims option to enforce required claims. Monitor vendor and NVD advisories for further updates. (Sources: OSV, NVD)
PatchBriefing score
4.7 / 10 · Medium
Official CVSS: 8.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Why this score
The advisory reports a CVSS 3.1 base score of 8.1 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N), reflecting high impact to confidentiality and integrity when an attacker can present a validly signed token. PatchWire's composite score for this advisory is 4.7; contributing factors include the CVSS base score and the fact that no user interaction is required. Known-exploited and public-exploit flags are false in the supplied facts. (Sources: OSV, NVD)
Affected versions
- fast-jwt ≥ 0 < 6.3.0
- vulnerable
- ≥ 6.3.0
- patched
Reported fixes
The issue is fixed in 6.3.0. The opt-in requiredClaims option can block missing claims and mitigate this issue if enabled. Signature verification is not bypassed by the bug. If you cannot immediately upgrade, enable requiredClaims (where feasible) and validate that accepted tokens have payloads that are JSON objects. (Sources: OSV, NVD)
How this was built
2 source records were collected, matched and used to prepare the report above.
-
OSV.dev database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email