AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-107720.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 7.4CVSS 3.1 · security-advisories@github.com
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSDeferredModified Oct 09, 2026

Disclosure summary

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.1, fast-jwt createVerifier accepts an unsigned JWT when key is an empty string or null and algorithms is a non-empty allowlist. Falsy synchronous keys bypass prepareKeyOrSecret, allowedAlgorithms remains active, hasKey is false, and the empty signature avoids the verifySignature gate. An attacker can therefore submit a token containing arbitrary claims without possessing a signing key, resulting in authentication or authorization bypass. Claim validators still run, and non-empty keys, an empty key without algorithms, and the async key resolver path do not have this behavior. This issue is fixed in version 6.3.1.

Source-reported weakness categories

CWE-20, CWE-347

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

NIST National Vulnerability Database · NVD-CVE-2026-107720

Open original source · Updated Oct 09, 2026

Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.

GitHub Reviewed Security Advisories · GHSA-8wpc-h4q6-8fxv

Open original source · Updated Oct 08, 2026

fast-jwt: createVerifier accepts unsigned JWTs when key is '' or null and algorithms is explicitly set

Source severity: HIGH / 0

EcosystemPackageAffected rangeFirst patched
npmfast-jwt6.3.1

Original records & references

PUBLISHED 2026-10-08T18:17:28-04:00
MODIFIED 2026-10-09T11:17:08-04:00
INGESTED 2026-10-10T20:55:03-04:00