Junglewise Threat Intelligence

CVE-2026-35039: fast-jwt cacheKeyBuilder collision identity mixup

CVE-2026-35039 · Severity: low · CVSS 3.1 · Published 2026-04-03

Technologies: fast-jwt (npm). Vendors: npm.

Executive brief

fast-jwt is a Node.js library for signing and verifying JSON Web Tokens (JWTs), commonly used in authentication systems to verify user identity. When caching is enabled with a poorly-designed custom cache key builder, two different users' tokens can incorrectly map to the same cache entry, causing the library to return one user's identity/permissions when verifying another user's token. This can lead to user impersonation, privilege escalation, or unauthorized data access across tenants.

Technical details

The vulnerability is a cache collision issue in the verifier's cacheKeyBuilder mechanism (src/verifier.js). When caching is enabled and a developer supplies a custom cacheKeyBuilder that produces non-unique keys for different tokens, the verifier returns the cached payload of a previously-verified token instead of validating and returning the current token's payload. For example, if two tokens for different users (userA and userB) both produce the cache key "aud=admin", verifying userB's token will return userA's cached claims. The vulnerability requires both caching to be explicitly enabled and a custom cacheKeyBuilder to be configured; the default caching behavior uses secure hashing and is not affected. No authentication bypass is required—attackers only need to submit valid JWTs with payloads that collide on the cache key.

Affected products

  • nearform fast-jwt 0.0.1 to 6.1.0 (patched in 6.2.0)

Timeline

  • 2026-04-03: disclosed
  • 2026-04-03: patched: Patch released in version 6.2.0, though library maintainers note this is primarily an education/warning update as the vulnerability stems from developer misuse of the API

References

Related threats