Executive brief
fast-jwt is a Node.js library for signing and verifying JSON Web Tokens (JWTs). The library's incomplete fix for a prior algorithm confusion vulnerability allows attackers to forge authentication tokens when RSA public keys contain leading whitespace—a common occurrence when keys are loaded from databases or configuration files. An attacker can forge tokens with arbitrary claims (e.g., elevated privileges) without knowing the private key, leading to authentication bypass and unauthorized access.
Technical details
This is a JWT algorithm confusion vulnerability caused by incomplete input validation in the publicKeyPemMatcher regex. The root cause is inconsistency: the private key detection path calls .trim() on the input before regex matching, but the public key detection path does not. When an RSA public key string has leading whitespace, the regex anchor (^) fails to match the "-----BEGIN" marker, causing the library to misclassify the RSA public key as an HMAC secret. An attacker with access to the public key can then forge HS256 tokens using the public key as the HMAC secret, bypassing authentication. The attack requires network access to a vulnerable endpoint; no user interaction or prior authentication is needed. Leading whitespace in PEM keys is common in real-world deployments (database text columns, YAML multiline strings, environment variables, copy-paste). The vulnerability was patched in version 6.2.0 by adding .trim() to the public key matching path.
Affected products
- NearForm fast-jwt <= 6.1.0
Timeline
- 2026-04-02: advisory
- 2026-04-02: patched: patched in version 6.2.0