Fast-jwt, Authentication Bypass, CVE-2026-107720 (Critical) -DC-Oct2026-2981

Listen to this Post

CVE-2026-107720 represents a critical authentication and authorization bypass vulnerability residing in the popular fast-jwt library for Node.js up to version 6.3.0.
The core flaw occurs during the initialization of the token verifier via the createVerifier function when a developer specifies a falsy synchronous key value such as an empty string or null, combined with an explicitly configured non-empty algorithms allowlist.
Under standard secure configurations, supplying a falsy key or omitting the key should cause the verifier to fail closed, safely rejecting incoming tokens.
However, in the affected versions, four specific cooperating code paths interact in an unintended manner to completely undermine this security guarantee.
First, when the key is provided as a falsy synchronous value like an empty string or null, the initial type checks allow execution to pass, but the conditional guard checking for the presence of the key bypasses the call to the internal prepareKeyOrSecret function entirely.
Consequently, the safety checks designed to reject empty secrets for synchronous keys are never reached or executed.
Second, because the key parameter is falsy, the library skips its automatic algorithm detection mechanism, allowing the caller-supplied algorithms allowlist array to remain active in the validation context.
Third, because no valid key object is instantiated, the internal boolean flag indicating the presence of a key evaluates to false, which under normal code logic would trigger a missing key error if a signature were present.
However, if an attacker crafts and presents an entirely unsigned token containing only a header and a payload separated by a trailing dot and no signature, the signature string evaluates to an empty value.
Because both the key presence flag and the signature string are falsy or empty, the verification branch checks are skipped completely without throwing any error.
Fourth, the actual cryptographic signature verification function is strictly gated behind a condition that requires the signature string to be truthy.
Since the attacker’s supplied token contains an empty signature string, this condition evaluates to false, causing the cryptographic verification function to be bypassed entirely without execution.
As a result of this dangerous asymmetry between the signer and verifier logic, the library accepts unsigned JWT tokens and successfully returns the attacker-controlled payload.
An attacker can completely forge arbitrary claims—including administrator privileges or root roles—without possessing any signing key whatsoever.
Ironically, the application of standard security best practices, such as explicitly defining an algorithm allowlist, acts as the exact trigger that enables this bypass.
Without an explicit algorithm allowlist, the default state fails closed and blocks the vulnerability, whereas setting an allowlist inadvertently keeps the validation gates open and trusts the unsigned input.

DailyCVE Form:

Platform: Fast-jwt library
Version: <= 6.3.0
Vulnerability: Authentication Bypass
Severity: Critical
date: October 8 2026

Prediction: Already Patched

What Undercode Say

Bash Commands and Codes

cd /tmp && git clone --depth 1 https://github.com/nearform/fast-jwt.git && cd fast-jwt && npm install
const { createVerifier } = require('.')
function unsigned(alg, claims) {
const h = Buffer.from(JSON.stringify({ alg, typ: 'JWT' })).toString('base64url')
const p = Buffer.from(JSON.stringify(claims)).toString('base64url')
return `${h}.${p}.`
}
const token = unsigned('HS256', { sub: 'attacker', admin: true, role: 'root' })
const verify = createVerifier({ key: '', algorithms: ['HS256'] })
console.log(verify(token))

Exploit: (Educational Purposes!)

An attacker exploits this vulnerability by passing an empty string ('') or `null` as the synchronous `key` option while configuring an explicit `algorithms` allowlist (e.g., ['HS256']). By generating a manipulated JSON Web Token with a trailing dot representing an empty, missing signature (header.payload.), the application’s verifier skips cryptographic validation entirely. Because the signature check condition evaluates to false and the falsy key bypasses secret preparation, the verification function returns the attacker’s forged claims payload directly, granting unauthorized administrative access or root privileges without needing any valid cryptographic signing key.

Protection: from this CVE

To protect applications from CVE-2026-107720, developers must immediately upgrade the `fast-jwt` library to version 6.3.1 or higher where input validation has been tightened. Additionally, developers should ensure that application code never passes falsy synchronous values (such as unvalidated environment variables like process.env.JWT_SECRET || '') directly into the `key` option of `createVerifier` without proper guarding. Verifiers should explicitly fail closed if a key is null or empty when algorithms are set, preventing unsigned tokens from being incorrectly trusted.

Impact:

The impact of CVE-2026-107720 is a full authentication and authorization bypass. Any application relying on vulnerable versions of `fast-jwt` that reads secrets from unset environment variables combined with an explicit algorithm allowlist will accept attacker-crafted, unsigned JWTs containing arbitrary claims. While secondary claim checks like expiration times still execute, the total loss of signature verification allows threat actors to forge tokens with arbitrary user identities, administrative privileges, and elevated roles, leading to complete compromise of protected backend services and resources.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top