HIGH🇵🇱 Wersja polska

CVE-2026-35042

CVSS 7.5v3.1pub. 2026-04-06upd. 2026-04-10

fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, fast-jwt does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that fast-jwt does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  • Nearform Fast Jwt

    APP
    Nearform
    < 6.2.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-34950CRITICAL9.1PL ✓same product

Nearform Fast-Jwt: podatność na atak JWT algorithm confusion (bypass patcha CVE-2023-48223)

CVE-2026-35039CRITICAL9.1PL ✓same product

Kolizja cache w fast-jwt prowadząca do błędnej identyfikacji użytkowników

CVE-2026-35040MEDIUM5.3same product

fast-jwt dostarcza szybką implementację JSON Web Token (JWT). Przed wersją 6.2.1 użycie określonych modyfikato...

CVE-2026-35041MEDIUM4.2same product

fast-jwt to biblioteka zapewniająca szybką implementację JSON Web Token (JWT). W wersjach od 5.0.0 do 6.2.0 is...

CVE-2023-48223MEDIUM5.9same product

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to version 3.3.2, the fast-jwt library does ...