CVE-2023-48223Patch(nearform / fast-jwt)

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nearform fast-jwt systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to version 3.3.2, the fast-jwt library does not properly prevent JWT algorithm confusion for all public key types. The 'publicKeyPemMatcher' in 'fast-jwt/src/crypto.js' does not properly match all common PEM formats for public keys. To exploit this vulnerability, an attacker needs to craft a malicious JWT token containing the HS256 algorithm, signed with the public RSA key of the victim application. This attack will only work if the victim application utilizes a public key containing the `BEGIN RSA PUBLIC KEY` header. Applications using the RS256 algorithm, a public key with a `BEGIN RSA PUBLIC KEY` header, and calling the verify function without explicitly providing an algorithm, are vulnerable to this algorithm confusion attack which allows attackers to sign arbitrary payloads which will be accepted by the verifier. Version 3.3.2 contains a patch for this issue. As a workaround, change line 29 of `blob/master/src/crypto.js` to include a regular expression.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fast-jwt

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Peaked 1d ago at 1 mentions (2026-04-06); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
fast-jwt

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-06: 1Mentions · 2026-10-01: 1Patch / Workaround · 2026-04-06: 1Technical Details · 2026-04-06: 104-0610-01
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Harsh Sanket@HarshSanket1

    CVE-2022-23540 in jsonwebtoken could allow signature validation bypass when jwt.verify() was used without defining allowed algorithms. CVE-2023-48223 affected fast-jwt with JWT algorithm confusion do not let an incoming token choose verification behavior.

    1001022
    7 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-34950: CRITICAL] Warning: Fast JWT 6.1.0 and earlier are vulnerable to CVE-2023-48223 exploit due to flawed implementation in publicKeyPemMatcher regex. Update for improved security.#cve,CVE-2026-34950,#cybersecurity https://cvefind.com/CVE-2026-34950

    Post summary

    The tweet warns of a critical flaw in Fast JWT 6.1.0 or earlier linked to CVE-2023-48223 and urges users to update for better security, but provides no exploit or PoC details.

    0000063
    619 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnearformfast-jwt-node.js-

Explore more