CVE-2026-107722: CVE-2026-107722: Algorithm Confusion via Non-Whitespace Prefix Bypass in fast-jwt
CVE-2026-107722: Algorithm Confusion via Non-Whitespace Prefix Bypass in fast-jwt Vulnerability ID: CVE-2026-107722 CVSS Score: 9.8 Published: 2026-10-08 A critical cryptographic vulnerability in fast-jwt versions 6
CVE-2026-107722: Algorithm Confusion via Non-Whitespace Prefix Bypass in fast-jwt
Vulnerability ID: CVE-2026-107722
CVSS Score: 9.8
Published: 2026-10-08
A critical cryptographic vulnerability in fast-jwt versions 6.2.x prior to 6.3.0 allows unauthenticated remote attackers to execute an asymmetric-to-symmetric algorithm confusion attack due to incomplete validation of leading non-whitespace prefixes.
TL;DR
Incomplete key sanitization in fast-jwt allows RSA-to-HMAC algorithm confusion, enabling complete authentication bypass.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-347
- Attack Vector: Network (AV:N)
- CVSS Score: 9.8 (Critical)
- Impact: Complete Authentication Bypass
- Exploit Status: Proof-of-Concept (PoC) available in test suite
- KEV Status: Not Listed
Affected Systems
- fast-jwt Node.js library
-
fast-jwt: >= 6.2.0 < 6.3.0 (Fixed in:
6.3.0)
Code Analysis
Commit: d96bbc6
Fix algorithm confusion with non-whitespace prefix
Exploit Details
- GitHub Security Advisory: GHSA-ww5h-9m49-7xx4: Algorithm Confusion via Non-Whitespace Prefix Bypass in fast-jwt
Mitigation Strategies
- Upgrade fast-jwt to 6.3.0 or higher
- Configure an explicit algorithm allowlist in verifier options
Remediation Steps:
- Verify the installed fast-jwt version in package.json
- Execute 'npm install [email protected]' to update the dependency
- Audit JWT verifier configurations and enforce explicit algorithm parameters
References
Read the full report for CVE-2026-107722 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.