External risk intelligence

fast-jwt Public Key Misclassification Vulnerability Allows Authentication Bypass.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-107722

The vulnerability affects a JWT (JSON Web Token) library used for authentication and authorization. JWT processing is a core component typically integrated into web applications, APIs, and microservices that are frequently exposed to the public internet to handle user sessions and identity verification.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in a JSON Web Token (JWT) library that could allow unauthorized access to systems. The issue arises when the library improperly handles public key formats, potentially enabling attackers to forge valid tokens and bypass authentication or authorization checks. While the library is used for security functions, the main concern is confirming if this specific component is in use and, if so, assessing the potential exposure.

  • Token validation errors can bypass security controls.
  • Consider if authentication libraries are in use.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can leverage this vulnerability by providing specially crafted public key material to a vulnerable application. If the application incorrectly interprets this material as a shared secret for HMAC signature verification, the attacker can then forge JWTs signed with this material, potentially bypassing authentication and authorization controls.

  • Requires attacker-controlled public key input.
  • Triggers when key is misclassified as HMAC secret.
  • Allows authentication and authorization bypass.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to forge JWTs that appear to be valid, leading to unauthorized access or actions. This may occur when the library incorrectly interprets an RSA public key as a secret key for HMAC signature verification.

  • JWT tokens could be forged.
  • An attacker could submit a crafted public key.
  • Authentication or authorization bypass.

Operational Fix

Recommended remediation, mitigation, and detection steps

Determine which teams own applications or services utilizing fast-jwt, confirm exposure to external networks, and prioritize remediation efforts based on business criticality and potential impact. The primary action is to identify all instances of the affected library and the accountable teams for each.

  • Ownership: Application or platform teams.
  • Verify: Identify all fast-jwt deployments.
  • Action: Plan upgrades during maintenance windows.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the fast-jwt library used for?

fast-jwt is a software library designed for Node.js environments to handle JSON Web Tokens. Developers use it to create, sign, and verify tokens that manage user identity and session data. It is a fundamental building block for securing APIs and microservices by ensuring that incoming requests are authenticated and authorized before granting access to protected system resources.

How does CVE-2026-107722 allow authentication bypass?

This vulnerability is classified as Improper Verification of Cryptographic Signature (CWE-347). It occurs when the library incorrectly misidentifies an RSA public key as an HMAC secret. Because the library fails to properly detect the key format, an attacker can exploit this flaw to sign tokens using the public key as if it were a shared secret. This allows them to forge valid-looking tokens and bypass security checks.

What triggers the vulnerability in fast-jwt?

The flaw is triggered when the library processes a public key containing unexpected content, such as comments or control characters, before the required PEM header. This causes the detection logic to fail and fall back to an HMAC verification process. The issue does not occur if the application is configured to only allow asymmetric algorithms, as this restricts the library from defaulting to the vulnerable HMAC fallback logic.

Is my application at risk from this vulnerability?

According to Halo Surface Signal, risk is elevated if your application uses fast-jwt to verify JWTs from untrusted sources, such as public-facing APIs or web services. Because JWT processing is essential for identity verification, any service exposed to the internet that utilizes the affected library versions (6.2.0 through 6.2.x) may be susceptible to unauthorized access attempts if attackers provide crafted token inputs.

How should I address this CVE-2026-107722 issue?

Begin by identifying all internal applications and services that include fast-jwt in their dependency tree. Once identified, prioritize updating the library to version 6.3.0 or later, which contains the fix for the key classification logic. If an immediate upgrade is not feasible, review your application configuration to ensure that only intended asymmetric algorithms are permitted for token validation.

References