DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-107722: CVE-2026-107722: Algorithm Confusion via Non-Whitespace Prefix Bypass in fast-jwt

CVE-2026-107722: Algorithm Confusion via Non-Whitespace Prefix Bypass in fast-jwt

Vulnerability ID: CVE-2026-107722
CVSS Score: 9.8
Published: 2026-10-08

A critical cryptographic vulnerability in fast-jwt versions 6.2.x prior to 6.3.0 allows unauthenticated remote attackers to execute an asymmetric-to-symmetric algorithm confusion attack due to incomplete validation of leading non-whitespace prefixes.

TL;DR

Incomplete key sanitization in fast-jwt allows RSA-to-HMAC algorithm confusion, enabling complete authentication bypass.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-347
  • Attack Vector: Network (AV:N)
  • CVSS Score: 9.8 (Critical)
  • Impact: Complete Authentication Bypass
  • Exploit Status: Proof-of-Concept (PoC) available in test suite
  • KEV Status: Not Listed

Affected Systems

  • fast-jwt Node.js library
  • fast-jwt: >= 6.2.0 < 6.3.0 (Fixed in: 6.3.0)

Code Analysis

Commit: d96bbc6

Fix algorithm confusion with non-whitespace prefix

Exploit Details

Mitigation Strategies

  • Upgrade fast-jwt to 6.3.0 or higher
  • Configure an explicit algorithm allowlist in verifier options

Remediation Steps:

  1. Verify the installed fast-jwt version in package.json
  2. Execute 'npm install fast-jwt@6.3.0' to update the dependency
  3. Audit JWT verifier configurations and enforce explicit algorithm parameters

References


Read the full report for CVE-2026-107722 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)