CVE-2026-107723: Silent Claim-Validator Bypass in NearForm fast-jwt via Array Payload Type Confusion
Vulnerability ID: CVE-2026-107723
CVSS Score: 8.1
Published: 2026-10-08
A high-severity type-confusion vulnerability exists in NearForm fast-jwt prior to version 6.3.0. The vulnerability allows attackers to bypass crucial claim validation steps (such as expiration, issuer, audience, and subject validations) by presenting a validly signed JSON Web Token structured as a JSON array instead of a JSON object. This occurs because the library's decoder fails to reject JSON arrays during type evaluation.
TL;DR
A type-confusion vulnerability in fast-jwt prior to 6.3.0 allows validly signed tokens structured as JSON arrays to completely bypass claim validations such as expiration (exp) and issuer (iss) verification.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-1287: Improper Validation of Specified Type of Input
- Attack Vector: Network (AV:N)
- CVSS Base Score: 8.1
- Exploit Status: Proof of Concept available
- CISA KEV Status: Not listed
- Remediation Status: Patched in v6.3.0
Affected Systems
- Applications utilizing fast-jwt library versions prior to 6.3.0
-
fast-jwt: < 6.3.0 (Fixed in:
6.3.0)
Code Analysis
Commit: 86e83ef
fix: reject array payloads explicitly to avoid silent validation bypass
@@ -62,7 +62,7 @@ function decode({ complete, checkTyp }, token) {
// 10. Verify that the resulting octet sequence is a UTF-8-encoded
// representation of a completely valid JSON object conforming to
// RFC 7159 [RFC7159]; let the JWT Claims Set be this JSON object.
- if (!payload || typeof payload !== 'object') {
+ if (!payload || typeof payload !== 'object' || Array.isArray(payload)) {
throw new TokenError(TokenError.codes.invalidPayload, 'The payload must be an object', { payload })
}
Mitigation Strategies
- Upgrade fast-jwt dependency to version 6.3.0 or later.
- Enforce strict claims verification using the opt-in requiredClaims configuration.
- Deploy WAF rules to detect and reject base64url-encoded array payloads (beginning with the Wy pattern).
Remediation Steps:
- Locate all node projects using fast-jwt as a dependency.
- Update package.json to reference fast-jwt version 6.3.0 or newer.
- Execute npm install or yarn install to update lockfiles.
- Ensure production environments are thoroughly redeployed and signature configurations are validated.
- Set requiredClaims for all configurations requiring expiration, issuer, and audience validations.
References
- GHSA-5hjw-83fp-phq9: Claim validation bypass
- PR #639: Fix array payload check
- fast-jwt v6.3.0 Release Notes
- NVD CVE-2026-107723 Details
- CVE-2026-107723 Record
Read the full report for CVE-2026-107723 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)