CVE-2026-18500Disclosure(fastify / fastify\/jwt)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch fastify fastify\/jwt systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

@fastify/jwt is a JSON Web Token plugin for Fastify. In versions before 10.2.2, a per-request verification key passed to request.jwtVerify({ key }) is silently overridden by the plugin's globally configured secret, because the option merge applies the global key last. Applications that use different keys for different authorization domains, for example separate user and admin keys, therefore accept a token signed with the global key on a route that explicitly requires another key. This lets an ordinary authenticated user cross a key-based trust boundary without knowing either secret. The issue is fixed in @fastify/jwt 10.2.2, where an explicit per-call key takes precedence over the global secret. Users should upgrade to 10.2.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fastify\/jwt

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 4 mentions (2026-08-15); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
fastify\/jwt

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-08-15: 4Mentions · 2026-08-17: 1Patch / Workaround · 2026-08-15: 2Technical Details · 2026-08-15: 4Technical Details · 2026-08-17: 108-1508-17
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-154
Disclosure2Patch2
2026-08-171
Disclosure1
Full discourse5 posts
  • Ulises Gascón@kom_256
    Patch

    🚨 High-severity security fix in @fastify/jwt@10.2.2 just released! Patches CVE-2026-18500: @fastify/jwt vulnerable to authorization bypass via global secret overriding the per-request key https://github.com/fastify/fastify-jwt/security/advisories/GHSA-j4cx-787j-xjqg

    Post summary

    The tweet announces a high‑severity security fix for CVE-2026‑18500, describing it as an authorization bypass exploit and providing a link to the official advisory.

    00021348
    5.5K followersView on X
  • NewNormal Security@NewScanTeam
    Disclosure

    NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 16 Aug 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 🖥️ Time-series monitoring database open to anyone who can reach the port — reads every metric you store, and wipes the history an incident would be rebuilt from (VictoriaMetrics) 📦 JWT check that ignores the key it was handed — a token signed with the app's general secret passes a check that demanded a per-tenant one (fastify CVE-2026-18500) 📦 Aborted uploads that never clean up — an unauthenticated client repeats a half-finished upload until the disk fills (fastify CVE-2026-19474, fastify CVE-2026-18549) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #ExposedInterface #CSO #REDTEAM

    Post summary

    The message discloses several new CVEs, highlighting technical details and potential misuse, but does not provide PoC or exploitation evidence.

    0000050
    5 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-18500 @fastify/jwt is a JSON Web Token plugin for Fastify. In versions before 10.2.2, a per-request verification key passed to request.jwtVerify({ key }) is silently overri… https://www.cve.org/CVERecord?id=CVE-2026-18500 ----- Traducción: CVE-2026-18500 @fa… https://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑18500, explaining that Fastify/JWT versions prior to 10.2.2 silently override a per‑request verification key, but it does not provide a PoC, exploit, patch, or active usage details.

    0000031
    98 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-18500 @fastify/jwt is a JSON Web Token plugin for Fastify. In versions before 10.2.2, a per-request verification key passed to request.jwtVerify({ key }) is silently overri… https://www.cve.org/CVERecord?id=CVE-2026-18500

    Post summary

    The text announces a new CVE (CVE-2026-18500) affecting the fastify/jwt plugin, detailing that before v10.2.2 a per‑request JWT verification key can be silently overridden, potentially leading to authentication bypass.

    000001.3K
    57.9K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨High - @fastify/jwt Per-Request Key Ignored, Enabling Trust-Boundary Bypass (CVE-2026-18500) In @fastify/jwt before 10.2.2, a per-request verification key passed to request.jwtVerify({ key }) is silently overridden by the plugin's global secret, because the option merge applies the global key last. Apps that use separate keys per authorization domain, such as distinct user and admin keys, will accept a token signed with the global key on a route that was meant to require a different key. The result is that an ordinary authenticated user can cross a key-based trust boundary, for example escalate to an admin route, without knowing either secret. It only affects apps using multiple keys with per-request overrides. CVSS 8.1. 👉Upgrade @fastify/jwt to 10.2.2, where an explicit per-call key takes precedence over the global secret.

    Post summary

    The advisory highlights that prior @fastify/jwt versions ignore per‑request keys, enabling a trust boundary bypass, and recommends upgrading to 10.2.2 to mitigate.

    00000109
    289 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfastifyfastify\/jwt-node.js-

Explore more