VendorsNearFormfast-jwtall versions
Vulnerabilities

NearForm fast-jwt

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2026-34950
fast-jwt has an incomplete fix for CVE-2023-48223: JWT Algorithm Confusion via Whitespace-Prefixed RSA Public Key
Published 2026-04-06 · Analyzed
9.1EPSS 0.003
CVE-2026-35039
fast-jwt Affected by Cache Confusion via cacheKeyBuilder Collisions Can Return Claims From a Different Token (Identity/Authorization Mixup)
Published 2026-04-06 · Analyzed
9.1EPSS 0.002
CVE-2026-35042
fast-jwt accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)
Published 2026-04-06 · Analyzed
7.5EPSS 0.002
CVE-2026-35041
ReDoS in fast-jwt when using RegExp in allowed* leading to CPU exhaustion during token verification
Published 2026-04-09 · Analyzed
6.5EPSS 0.004
CVE-2023-48223
fast-jwt JWT Algorithm Confusion
Published 2023-11-20 · Modified
5.9EPSS 0.007
CVE-2026-35040
fast-jwt: Stateful RegExp (/g or /y) causes non-deterministic allowed-claim validation (logical DoS)
Published 2026-04-09 · Analyzed
5.3EPSS 0.006