Junglewise Threat Intelligence

CVE-2025-30144: NearForm Fast-JWT improper iss claim validation

CVE-2025-30144 · Severity: low · CVSS 3.1 · Published 2025-03-19

Technologies: NearForm Fast-Jwt. Vendors: npm.

Executive brief

Fast-JWT is a JavaScript library for creating and verifying JSON Web Tokens (JWTs), which are commonly used to authenticate users and secure API requests. The library improperly validates the "iss" (issuer) claim, allowing attackers to craft fraudulent tokens that appear to come from legitimate issuers. An attacker can bypass authentication checks and forge tokens that applications will incorrectly accept as valid, potentially gaining unauthorized access to protected resources.

Technical details

The vulnerability is an improper input validation (CWE-20) flaw in Fast-JWT's iss claim validation logic. According to RFC 7519, the iss claim must be a string; however, Fast-JWT incorrectly accepts an array of strings as a valid iss value. An attacker can craft a JWT with an iss claim structured as ['https://attacker-domain/', 'https://valid-iss'], which will be validated as legitimate. The vulnerability is exploitable over the network with moderate attack complexity, particularly when used alongside libraries like get-jwks that do not independently validate the iss claim. An attacker with no authentication or privileges can forge arbitrary JWT payloads and bypass issuer validation, compromising data integrity and authentication mechanisms.

Affected products

  • NearForm Fast-JWT <5.0.6

Timeline

  • 2025-03-19: disclosed
  • 2025-03-19: patched: Fixed in version 5.0.6

References

Related threats