CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-107722

CVE-2026-107722: Algorithm Confusion via Non-Whitespace Prefix Bypass in fast-jwt

Amit Schendel
Amit Schendel
Senior Security Researcher

Oct 9, 2026·5 min read·2 visits

Executive Summary (TL;DR)

Incomplete key sanitization in fast-jwt allows RSA-to-HMAC algorithm confusion, enabling complete authentication bypass.

A critical cryptographic vulnerability in fast-jwt versions 6.2.x prior to 6.3.0 allows unauthenticated remote attackers to execute an asymmetric-to-symmetric algorithm confusion attack due to incomplete validation of leading non-whitespace prefixes.

Vulnerability Overview

The fast-jwt library is a high-performance JSON Web Token implementation designed for Node.js environments. In versions 6.2.x prior to 6.3.0, it contains a critical vulnerability that allows asymmetric-to-symmetric algorithm confusion. This attack vector allows an unauthenticated remote attacker to bypass cryptographic signature verification and gain unauthorized access to target applications.

The vulnerability is rooted in how the library auto-detects the format of the key supplied to the verifier. When a verifier is initialized without an explicit, restrictive algorithm allowlist, it evaluates the key format to determine whether to perform asymmetric (RS*/ES*) or symmetric (HS*) signature verification. Because the auto-detection routine depends on matching anchored regular expressions, the presence of specific non-whitespace leading prefixes causes the parser to fail back to symmetric validation.

An attacker who knows or can obtain the server public key can exploit this fallback. By signing a forged token with the public key as the shared HMAC secret, the attacker triggers verification using the symmetric pipeline. This completely invalidates the integrity guarantees of the token and allows full system access.

Root Cause Analysis

The root cause of CVE-2026-107722 is an incomplete patch for an earlier key-parsing vulnerability, CVE-2026-34950. The previous security fix attempted to protect the anchored regular expressions by calling String.prototype.trim() on the key input before matching headers. However, the standard ECMAScript trim operation only removes whitespace characters, leaving any leading non-whitespace characters intact.

Key detection regular expressions are anchored to the start of the string using the '^' character. For example, the parser identifies public keys via /^-----BEGIN(?: (RSA))? PUBLIC KEY-----/. When the key contains non-whitespace prefixes—such as database comments, control characters, or protocol headers—the regular expression fails to match.

Because the anchored check fails, the library assumes the key is not a PEM-formatted asymmetric key. Instead of throwing an error or rejecting the invalid input, the verification engine falls back to treating the key as a raw, symmetric HMAC shared secret. The entire prefixed public key string is then registered as the symmetric HMAC key.

Code Analysis

In vulnerable versions of src/crypto.js, the key sanitization code relies entirely on standard string trimming:

// Vulnerable logic in fast-jwt < 6.3.0
function performDetectPublicKeyAlgorithms(key) {
  const trimmedKey = key.trim()
  const publicKeyPemMatch = trimmedKey.match(publicKeyPemMatcher) 
  // If key begins with non-whitespace prefix, publicKeyPemMatch is null
  if (!publicKeyPemMatch) {
    return hsAlgorithms // Falls back to symmetric HMAC algorithms
  }
}

In the patched version (v6.3.0), the library introduces a centralized, non-anchored PEM locator function. This function scans the entire key string to identify the position of the standard PEM boundary, preventing bypasses caused by arbitrary prefixes:

// Patched logic in fast-jwt 6.3.0
const pemBeginMatcher = /-----BEGIN [A-Z0-9 ]+?-----/
 
function locatePem(trimmedKey) {
  const pemStart = trimmedKey.search(pemBeginMatcher)
  if (pemStart === -1) {
    return { pem: null, isRawSecret: true }
  }
  return { pem: trimmedKey.slice(pemStart), isRawSecret: false }
}

The update ensures that any string containing a valid PEM block is correctly isolated and processed as an asymmetric key, regardless of preceding data. It also throws a definitive TokenError if a PEM header is recognized but is unsupported, eliminating silent fallbacks.

Exploitation Methodology

An attacker targets applications that do not enforce explicit verification algorithms. If the application loads a public key containing a leading comment or non-whitespace prefix, the attacker can leverage the algorithm confusion flaw.

The attacker retrieves the public key and generates a malicious JWT. The header is configured with the 'alg' field set to 'HS256' to instruct the server to use symmetric verification. The payload is configured with arbitrary claims, such as administrative access privileges.

The attacker signs the token using HMAC-SHA256, utilizing the full, prefixed public key string as the shared secret key. When the application receives the token, the fast-jwt verifier evaluates the header algorithm as 'HS256', resolves the verification key as a symmetric secret due to the failed PEM check, and verifies the signature successfully.

Impact Assessment

The impact of successful exploitation is a complete compromise of the token validation mechanism. An attacker can forge JWTs containing arbitrary identity claims and permissions, bypassing authentication and authorization controls without possessing the server private key.

This flaw is classified under CWE-347 (Improper Verification of Cryptographic Signature) and has a CVSS v3.1 base score of 9.8. Exploitation is highly reliable, requiring no user interaction and low attack complexity. Applications that automatically load public keys from external databases or environment configuration strings are particularly exposed if those inputs contain metadata prefixes.

Remediation and Mitigation

To resolve this vulnerability, upgrade fast-jwt to version 6.3.0 or higher. The updated package eliminates the vulnerable validation paths by extracting the PEM block correctly using the non-anchored locatePem implementation.

As a defense-in-depth measure, developers must configure verifiers with an explicit list of allowed algorithms. This completely disables key auto-detection and prevents algorithm-confusion bypasses by rejecting any token signed with an unexpected algorithm:

const { createVerifier } = require('fast-jwt')
const fs = require('fs')
 
const publicKey = fs.readFileSync('public.pem', 'utf8')
 
// Secure configuration bypassing auto-detection
const verify = createVerifier({
  key: publicKey,
  algorithms: ['RS256']
})

Official Patches

nearformPull Request #632 fixing non-whitespace prefix parsing

Fix Analysis (1)

Technical Appendix

CVSS Score
9.8/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Systems

fast-jwt Node.js library

Affected Versions Detail

Product
Affected Versions
Fixed Version
fast-jwt
nearform
>= 6.2.0 < 6.3.06.3.0
AttributeDetail
CWE IDCWE-347
Attack VectorNetwork (AV:N)
CVSS Score9.8 (Critical)
ImpactComplete Authentication Bypass
Exploit StatusProof-of-Concept (PoC) available in test suite
KEV StatusNot Listed

MITRE ATT&CK Mapping

T1606.001Forge Web Credentials: Web Tokens
Credential Access
T1556Modify Authentication Process
Defense Evasion
CWE-347
Improper Verification of Cryptographic Signature

The application does not properly verify the cryptographic signature of the JSON Web Token (JWT) due to algorithm confusion, allowing unauthorized claims to be trusted as authentic.

Known Exploits & Detection

GitHub Security AdvisoryGHSA-ww5h-9m49-7xx4: Algorithm Confusion via Non-Whitespace Prefix Bypass in fast-jwt

Vulnerability Timeline

Vulnerability reported and PR #632 created
2026-07-27
Patch merged and version 6.3.0 released
2026-07-28
CVE-2026-107722 officially published
2026-10-08

References & Sources

  • [1]GitHub Security Advisory GHSA-ww5h-9m49-7xx4
  • [2]GitHub Pull Request #632
  • [3]Fix Commit d96bbc6
Related Vulnerabilities
CVE-2026-34950

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•7 minutes ago•CVE-2026-107721
5.9

CVE-2026-107721: Time Validation Bypass in NearForm fast-jwt due to Loose Temporal Option Validation

NearForm fast-jwt prior to version 6.3.0 is vulnerable to an input validation flaw where configuring verifier properties (such as clockTolerance, clockTimestamp, and cacheTTL) with non-finite values like Infinity or NaN allows attackers to bypass temporal claim validations, including expiration (exp) and activation (nbf) boundaries. This validation bypass can result in unauthorized session persistence and cache poisoning.

Amit Schendel
Amit Schendel
0 views•6 min read
•about 2 hours ago•CVE-2026-107720
7.4

CVE-2026-107720: Signature Verification Bypass in NearForm fast-jwt

CVE-2026-107720 is a critical signature verification bypass vulnerability in NearForm's fast-jwt Node.js library. Under specific configurations where the token verifier is initialized with a falsy cryptographic key (such as an empty string or null) and a non-empty algorithms allowlist, the library erroneously skips signature validation. This allows unauthenticated remote attackers to submit fabricated, unsigned JSON Web Tokens and bypass the authorization boundary of the application entirely.

Amit Schendel
Amit Schendel
5 views•7 min read
•about 3 hours ago•CVE-2026-107715
6.8

CVE-2026-107715: Information Disclosure and Credential Leakage in Ruby Mechanize via Cross-Origin Redirections

Ruby Mechanize prior to version 2.14.1 contains an information disclosure vulnerability. When executing cross-origin HTTP redirects, global headers configured on the Mechanize agent (such as Authorization or Session Cookies) are dynamically re-applied to the subsequent request, bypassing the internal header-stripping logic. An attacker who controls a redirection endpoint can capture sensitive bearer tokens or cookies.

Alon Barad
Alon Barad
6 views•7 min read
•about 4 hours ago•CVE-2026-107399
6.8

CVE-2026-107399: Information Disclosure via HTML Meta-Refresh in Ruby Mechanize

An origin trust boundary failure in the Ruby mechanize library (prior to v2.14.1) allows unauthenticated remote web servers to harvest sensitive global request headers, such as Authorization Bearer tokens and cookies, by utilizing HTML-level meta-refresh redirection tags. Standard HTTP-level redirect boundaries were not applied to document-level redirects, creating a vector for cross-origin credential leakage during automated crawls.

Amit Schendel
Amit Schendel
5 views•5 min read
•about 5 hours ago•CVE-2026-107718
6.1

CVE-2026-107718: Open Redirect Vulnerability in @adonisjs/http-server

CVE-2026-107718 is a medium-severity Open Redirect vulnerability in the core HTTP server package of the AdonisJS Node.js framework. Prior to versions 8.2.3 and 9.3.0, the framework built route paths by directly interpolating dynamic parameters and wildcard segments without URI encoding. If an application routes attacker-controlled input directly to a dynamic first path segment and uses the generated route URL as a redirect destination, a leading slash can produce a scheme-relative external URL. Modern web browsers process scheme-relative URLs by redirecting the client to the specified external domain, exposing users to credential harvesting, social engineering, and session hijacking. This vulnerability affects all applications running unpatched configurations where input validation is not explicitly implemented before generating paths.

Alon Barad
Alon Barad
6 views•6 min read
•about 6 hours ago•CVE-2026-107725
8.7

CVE-2026-107725: Remote Code Execution via Authorization Bypass in Hazelcast Predicates API

CVE-2026-107725 is a critical security bypass in Hazelcast where missing authorization checks in the MapPermission class permit unprivileged clients to issue queries containing aggregators or projections. This architectural oversight allows attackers to run arbitrary code on the cluster servers under the privileges of the active Hazelcast process.

Amit Schendel
Amit Schendel
6 views•7 min read