Firmis Labs[verified]@FirmisLabsPatch
The message references CVE-2026-34950, provides its NIST CVSS score, and recommends upgrading fast-jwt to the latest version as a mitigation.
Firmis Labs[verified]@FirmisLabsGeneral
The text lists the CVE identifier with its NVD link, offering no additional detail or context.
Gray Hats@the_yellow_fallDisclosure
The post announces CVE‑2026‑34950, a critical 9.1 CVSS flaw in fast‑jwt that permits authentication bypass via leading whitespace, without evidence of exploitation or available patch.
0day Signal@0dayPublishingDisclosure
The post describes a flaw in fast‑jwt where whitespace in JWT headers bypasses RSA key validation, allowing forged tokens via symmetric HMAC, but no PoC, exploit, or patch information is provided.
CVE@CVEnewDisclosure
The post announces CVE‑2026‑34950, noting a regex flaw in fast‑jwt’s public key PEM matcher, but does not provide PoC, exploit, patch, or active exploitation information.
CVEFind.com@CveFindComPatch
Fast JWT 6.1.0 and earlier are vulnerable due to a regex flaw (CVE-2023-48223); the post urges an update to mitigate the risk.
PulsePatch.io@pulsepatchioDisclosure
The post announces that fast-jwt’s fix for CVE‑2026‑34950 is incomplete, potentially allowing an authentication bypass through algorithm confusion.