Dev.to Security 🔐 Cybersecurity 👁 0 📖 2 min read

CVE-2026-107720: CVE-2026-107720: Signature Verification Bypass in NearForm fast-jwt

CVE-2026-107720: Signature Verification Bypass in NearForm fast-jwt Vulnerability ID: CVE-2026-107720 CVSS Score: 7.4 Published: 2026-10-08 CVE-2026-107720 is a critical signature verification bypass vulnerability i

CVE-2026-107720: Signature Verification Bypass in NearForm fast-jwt

Vulnerability ID: CVE-2026-107720
CVSS Score: 7.4
Published: 2026-10-08

CVE-2026-107720 is a critical signature verification bypass vulnerability in NearForm's fast-jwt Node.js library. Under specific configurations where the token verifier is initialized with a falsy cryptographic key (such as an empty string or null) and a non-empty algorithms allowlist, the library erroneously skips signature validation. This allows unauthenticated remote attackers to submit fabricated, unsigned JSON Web Tokens and bypass the authorization boundary of the application entirely.

TL;DR

A flaw in fast-jwt prior to 6.3.1 allows attackers to forge JSON Web Tokens and bypass authorization checks entirely if the library is configured with a blank/null key and an explicit list of allowed algorithms.

⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-347 (Improper Verification of Cryptographic Signature)
  • Attack Vector: Network (AV:N)
  • CVSS v3.1 Score: 7.4 (High)
  • Exploit Status: Proof of Concept (PoC) available
  • CISA KEV Status: Not listed
  • Impact: Complete authentication and authorization bypass

Affected Systems

  • All Node.js applications using NearForm fast-jwt versions prior to 6.3.1
  • fast-jwt: < 6.3.1 (Fixed in: 6.3.1)

Code Analysis

Commit: e22a151

Fix validation logical flaw when key is falsy and non-none algorithm list is used

Mitigation Strategies

  • Upgrade the fast-jwt dependency to version 6.3.1 or higher immediately.
  • Implement robust environment variable validation to crash the application if cryptographic keys are resolved as empty or null.
  • Explicitly omit or restrict the use of the 'none' algorithm unless it is required by design.

Remediation Steps:

  1. Locate the package.json file of the application and check the fast-jwt version.
  2. Execute the package manager update command: 'npm install [email protected]' or equivalent.
  3. Audit the application bootstrap code to ensure that the secrets supplied to 'createVerifier' are verified as non-empty during initialization.
  4. Re-deploy the application and confirm through logging that no warning or key initialization errors are present.

References

Read the full report for CVE-2026-107720 on our website for more details including interactive diagrams and full exploit analysis.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.