{"id":"CVE-2026-107724","summary":"fast-jwt treats raw public JWK JSON as an HMAC secret, enabling HS256 token forgery","details":"fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.2.4, fast-jwt can classify raw serialized public JWK or JWKS JSON as an HMAC secret because src/crypto.js performDetectPublicKeyAlgorithms treats non-PEM strings as symmetric key material. If HS256 is explicitly allowed or inferred, an attacker who knows the exact serialized public-key bytes can use those bytes as an HMAC key and create a token containing arbitrary claims that createVerifier accepts. Serialization ordering or whitespace differences can prevent exploitation, and applications using supported PEM keys with an asymmetric-only algorithm allowlist are not affected. This issue is fixed in version 6.3.0.","aliases":["GHSA-g3jj-5cmm-3hxx"],"modified":"2026-10-09T10:46:09.433927530Z","published":"2026-10-08T21:53:01.909Z","database_specific":{"cwe_ids":["CWE-347"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107724.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107724.json"},{"type":"FIX","url":"https://github.com/nearform/fast-jwt/commit/10f9591349199ed2ab9fa1748ce92cdca697f6cf"},{"type":"FIX","url":"https://github.com/nearform/fast-jwt/pull/636"},{"type":"WEB","url":"https://github.com/nearform/fast-jwt/releases/tag/v6.3.0"},{"type":"ADVISORY","url":"https://github.com/nearform/fast-jwt/security/advisories/GHSA-g3jj-5cmm-3hxx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107724"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nearform/fast-jwt","events":[{"introduced":"044bf42c8e0a2eda8afc0819f97ae435c4214e3c"},{"fixed":"b351e31a755cdce457e0d25ce22b139bbcf469da"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"6.2.4"},{"fixed":"6.3.0"}]}}],"versions":["v6.2.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107724.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}