DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-107723: CVE-2026-107723: Silent Claim-Validator Bypass in NearForm fast-jwt via Array Payload Type Confusion

CVE-2026-107723: Silent Claim-Validator Bypass in NearForm fast-jwt via Array Payload Type Confusion

Vulnerability ID: CVE-2026-107723
CVSS Score: 8.1
Published: 2026-10-08

A high-severity type-confusion vulnerability exists in NearForm fast-jwt prior to version 6.3.0. The vulnerability allows attackers to bypass crucial claim validation steps (such as expiration, issuer, audience, and subject validations) by presenting a validly signed JSON Web Token structured as a JSON array instead of a JSON object. This occurs because the library's decoder fails to reject JSON arrays during type evaluation.

TL;DR

A type-confusion vulnerability in fast-jwt prior to 6.3.0 allows validly signed tokens structured as JSON arrays to completely bypass claim validations such as expiration (exp) and issuer (iss) verification.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-1287: Improper Validation of Specified Type of Input
  • Attack Vector: Network (AV:N)
  • CVSS Base Score: 8.1
  • Exploit Status: Proof of Concept available
  • CISA KEV Status: Not listed
  • Remediation Status: Patched in v6.3.0

Affected Systems

  • Applications utilizing fast-jwt library versions prior to 6.3.0
  • fast-jwt: < 6.3.0 (Fixed in: 6.3.0)

Code Analysis

Commit: 86e83ef

fix: reject array payloads explicitly to avoid silent validation bypass

@@ -62,7 +62,7 @@ function decode({ complete, checkTyp }, token) {
     // 10.  Verify that the resulting octet sequence is a UTF-8-encoded
     //      representation of a completely valid JSON object conforming to
     //      RFC 7159 [RFC7159]; let the JWT Claims Set be this JSON object.
-    if (!payload || typeof payload !== 'object') {
+    if (!payload || typeof payload !== 'object' || Array.isArray(payload)) {
       throw new TokenError(TokenError.codes.invalidPayload, 'The payload must be an object', { payload })
     }
Enter fullscreen mode Exit fullscreen mode

Mitigation Strategies

  • Upgrade fast-jwt dependency to version 6.3.0 or later.
  • Enforce strict claims verification using the opt-in requiredClaims configuration.
  • Deploy WAF rules to detect and reject base64url-encoded array payloads (beginning with the Wy pattern).

Remediation Steps:

  1. Locate all node projects using fast-jwt as a dependency.
  2. Update package.json to reference fast-jwt version 6.3.0 or newer.
  3. Execute npm install or yarn install to update lockfiles.
  4. Ensure production environments are thoroughly redeployed and signature configurations are validated.
  5. Set requiredClaims for all configurations requiring expiration, issuer, and audience validations.

References


Read the full report for CVE-2026-107723 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)