NewNormal Security[verified]@NewScanTeamDisclosure
The message discloses several new CVEs, highlighting technical details and potential misuse, but does not provide PoC or exploitation evidence.
Upwind Security MDR[verified]@UpwindMDRPatch
The advisory highlights that prior @fastify/jwt versions ignore per‑request keys, enabling a trust boundary bypass, and recommends upgrading to 10.2.2 to mitigate.
Ulises Gascón@kom_256Patch
The tweet announces a high‑severity security fix for CVE-2026‑18500, describing it as an authorization bypass exploit and providing a link to the official advisory.
Infoflowcloud@infoflowcloudDisclosure
The post announces CVE‑2026‑18500, explaining that Fastify/JWT versions prior to 10.2.2 silently override a per‑request verification key, but it does not provide a PoC, exploit, patch, or active usage details.
CVE@CVEnewDisclosure
The text announces a new CVE (CVE-2026-18500) affecting the fastify/jwt plugin, detailing that before v10.2.2 a per‑request JWT verification key can be silently overridden, potentially leading to authentication bypass.