Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.9 Node.js & npm GHSA-8wpc-h4q6-8fxv CVE-2026-107720

fast-jwt: createVerifier accepts unsigned JWTs when key is empty and algorithms is set (CVE-2026-107720)

A vulnerability in fast-jwt's createVerifier can allow an attacker to submit unsigned JWTs that bypass signature verification when the verifier key is an empty string or null and an algorithms allowlist is provided. The issue is fixed in 6.3.1. [CVE-2026-107720] [GHSA-8wpc-h4q6-8fxv]

Synthesized by AI from 2 sources · updated 1 hour ago

AI summary

fast-jwt contains a verification bug (CVE-2026-107720 / GHSA-8wpc-h4q6-8fxv) where createVerifier can accept unsigned tokens under specific conditions. This briefing summarizes impact, technical cause, affected releases and recommended actions.

What happened

When createVerifier is called with a synchronous key that is an empty string or null and with a non-empty algorithms allowlist, fast-jwt treats the key as falsy and bypasses prepareKeyOrSecret. The verifier's hasKey flag is false and the empty signature avoids the verifySignature check, allowing a token with an empty signature to pass verification. Claim validators still run, but an attacker can submit tokens with arbitrary claims without possessing a signing key, resulting in authentication or authorization bypass under those conditions.

Technical cause

A falsy synchronous key (empty string or null) causes the implementation to skip the synchronous key-preparation path (prepareKeyOrSecret). With algorithms explicitly set (non-empty allowlist) and no prepared key, the code leaves hasKey false while allowedAlgorithms remains active; an empty signature then passes the signature check. The behavior does not occur for non-empty keys, when algorithms is empty, or when using the async key resolver path.

Why it matters

An attacker can present a JWT carrying arbitrary claims and, in the vulnerable configuration, have it accepted without a valid signature. This enables authentication or authorization bypass for systems that rely on fast-jwt's createVerifier for token validation. Claim validators still run, so some checks may still block certain tokens, but signature-based assurance is effectively removed in the described scenario.

Who is affected

Applications using the fast-jwt npm package and calling createVerifier with a synchronous key that may be an empty string or null while also passing a non-empty algorithms allowlist are affected. Non-empty keys, an empty algorithms allowlist, and the async key resolver path are not affected.

Discovery and timeline

This issue was published to public vulnerability databases on 2026-10-08 and 2026-10-08 (see sources). The advisory entries for this vulnerability are recorded under the identifiers CVE-2026-107720 and GHSA-8wpc-h4q6-8fxv.

Affected versions

All releases of fast-jwt introduced at version 0 up to but not including 6.3.1 are affected. The fixed release is 6.3.1.

Fixes and mitigation

A code fix is available in fast-jwt version 6.3.1. As a mitigation until you can update, avoid calling createVerifier with a synchronous key value that may be an empty string or null; ensure the verifier key is a non-empty value or use the async key resolver path. The advisory indicates the behavior does not occur for non-empty keys, an empty algorithms list, or the async resolver.

Recommended action

Upgrade fast-jwt to 6.3.1 as soon as practicable. If immediate upgrade is not possible, ensure verifier calls provide a non-empty signing key or use the async key resolver, and review token validation configurations to avoid passing a non-empty algorithms allowlist with a potentially empty key.

PatchBriefing score

4.9 / 10 · Medium

Official CVSS: 7.4

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Why this score

Severity is based on CVSS v3.1 and Patchwire scoring. The advisory lists a CVSS base score of 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N). The computed Patchwire score is 4.9; contributing factors include the CVSS base (7.4), that the issue can be triggered by an unauthenticated remote attacker, and that no user interaction is required. The advisory records no known public exploit or known active exploitation. [sources: 4095, 31977]

Affected versions

fast-jwt ≥ 0 < 6.3.1
vulnerable
≥ 6.3.1
patched

Reported fixes

A code fix is available in fast-jwt version 6.3.1. As a mitigation until you can update, avoid calling createVerifier with a synchronous key value that may be an empty string or null; ensure the verifier key is a non-empty value or use the async key resolver path. The advisory indicates the behavior does not occur for non-empty keys, an empty algorithms list, or the async resolver.

How this was built

2 source records were collected, matched and used to prepare the report above.

  • OSV.dev database
  • NVD (NIST) database
Unified report
fast-jwt: createVerifier accepts unsigned JWTs when key is empty and algorithms is set (CVE-2026-107720)
1 article · 2 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email