Junglewise Threat Intelligence

CVE-2026-44351: nearform fast-jwt authentication bypass in async key resolver

CVE-2026-44351 · Severity: critical · CVSS 9.1 · Published 2026-05-13

Technologies: Nearform Fast-Jwt. Vendors: npm.

Executive brief

A security flaw in the fast-jwt library allows attackers to bypass authentication and gain unauthorized access to applications. By providing a specially crafted token signed with an empty key, an attacker can impersonate any user, including administrators, if the application's key lookup fails or returns an empty value. This could lead to full account takeover and unauthorized access to sensitive customer data.

Technical details

The vulnerability exists in the asynchronous key-resolver flow within `src/verifier.js`. When a developer-provided `key` callback returns an empty string (`''`) or a zero-length Buffer, the library fails to validate the key length and defaults to HMAC algorithms (HS256, HS384, HS512). An attacker can then sign a JWT using an empty HMAC secret, which the library accepts as valid. This occurs because `prepareKeyOrSecret` does not perform a length check on the derived secret before passing it to Node's `crypto.createSecretKey`. The issue is specifically present in the async path; the synchronous path correctly rejects falsy keys. A patch is available in version 6.2.4.

Affected products

  • nearform fast-jwt <= 6.2.3

Timeline

  • 2026-04-29: disclosed
  • 2026-05-06: advisory: GHSA-gmvf-9v4p-v8jc published
  • 2026-05-14: other: Advisory updated

References

Related threats