Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.9 Node.js & npm GHSA-g3jj-5cmm-3hxx CVE-2026-107724

fast-jwt treats raw public JWK JSON as HMAC secret — CVE-2026-107724

fast-jwt incorrectly classifies raw serialized public JWK/JWKS JSON as symmetric HMAC key material, allowing an attacker who knows the exact serialized bytes to forge HS256 tokens that verify. Fixed in 6.3.0. (CVE-2026-107724, GHSA-g3jj-5cmm-3hxx)

Synthesized by AI from 2 sources · updated 1 hour ago

AI summary

A vulnerability in fast-jwt can cause raw serialized public JWK or JWKS JSON to be treated as symmetric HMAC key material. This can let an attacker who knows the exact serialized public-key bytes create tokens that verify under HS256 when HS256 is permitted. The issue is tracked as CVE-2026-107724 / GHSA-g3jj-5cmm-3hxx and fixed in 6.3.0. [source_item_ids: 4101, 31981]

What happened

fast-jwt classified non-PEM serialized public JWK or JWKS JSON as a symmetric HMAC secret. If HS256 is explicitly allowed or inferred, an attacker who knows the exact serialized public-key bytes can use those bytes as an HMAC key to create a token with arbitrary claims that fast-jwt's verifier accepts. Serialization ordering or whitespace differences can prevent exploitation. [source_item_ids: 4101, 31981]

Technical cause

The library's detection logic treats non-PEM strings as symmetric key material (the function performDetectPublicKeyAlgorithms in src/crypto.js), so a raw serialized public JWK/JWKS JSON blob can be misclassified as an HMAC secret. That misclassification allows use of the raw bytes as an HMAC key when HS256 is permitted. [source_item_ids: 4101, 31981]

Why it matters

If an application allows HS256 (either explicitly or by algorithm inference) and accepts raw serialized public JWK/JWKS JSON, an attacker who can obtain the exact serialized bytes for a public key can forge tokens with arbitrary claims that the library will accept. Successful forgery can lead to authentication or authorization bypass in systems that rely on those tokens. The CVSS base score is 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N). [source_item_ids: 4101, 31981]

Who is affected

Projects using the fast-jwt npm package that accept raw serialized public JWK or JWKS JSON and permit HS256 (explicitly or via inference) are at risk. Applications that use supported PEM keys with an asymmetric-only algorithm allowlist are not affected. [source_item_ids: 4101, 31981]

Discovery and timeline

The vulnerability is recorded in OSV and NVD with publication dates in October 2026. The advisory entries are available from OSV.dev and NVD. No public exploit activity is reported in the sources. [source_item_ids: 4101, 31981]

Affected versions

fast-jwt versions introduced in 6.2.4 through the fix are affected; the issue is fixed in 6.3.0. [source_item_ids: 4101, 31981]

Fixes and mitigation

The vendor fixed the issue in 6.3.0. Applications that already use supported PEM keys and enforce an asymmetric-only algorithm allowlist are not affected. No public exploit is reported. [source_item_ids: 4101, 31981]

Recommended action

1) Upgrade fast-jwt to 6.3.0. 2) Audit token verification configuration: ensure HS256 is not permitted when accepting public JWK/JWKS input, and prefer supported PEM keys with an asymmetric-only algorithm allowlist. 3) If immediate upgrade is not possible, avoid accepting raw serialized public JWK/JWKS JSON as key material or ensure your verification code rejects symmetric algorithms for public-key inputs. These recommendations follow the conditions and mitigations described in the advisories. [source_item_ids: 4101, 31981]

PatchBriefing score

4.9 / 10 · Medium

Official CVSS: 7.4

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Why this score

The advisory lists a CVSS v3.1 base score of 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N). Patchwire's combined score is 4.9; component factors include the CVSS base (contribution 4.07), unauthenticated remote impact (0.6), and no user interaction required (0.2). There are no known exploited or public exploit indicators in the provided sources. [source_item_ids: 4101, 31981]

Affected versions

fast-jwt ≥ 6.2.4 < 6.3.0
vulnerable
fast-jwt
vulnerable
≥ 6.3.0
patched

Reported fixes

The vendor fixed the issue in 6.3.0. Applications that already use supported PEM keys and enforce an asymmetric-only algorithm allowlist are not affected. No public exploit is reported. [source_item_ids: 4101, 31981]

How this was built

2 source records were collected, matched and used to prepare the report above.

  • OSV.dev database
  • NVD (NIST) database
Unified report
fast-jwt treats raw public JWK JSON as HMAC secret — CVE-2026-107724
1 article · 2 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email