CVE-2026-34950Disclosure(nearform / fast-jwt)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nearform fast-jwt systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, the publicKeyPemMatcher regex in fast-jwt/src/crypto.js uses a ^ anchor that is defeated by any leading whitespace in the key string, re-enabling the exact same JWT algorithm confusion attack that CVE-2023-48223 patched.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-327

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fast-jwt

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 4 mentions (2026-04-06); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
fast-jwt

Deep dive

Activity timeline7 mentions / 4d
01234Mentions · 2026-04-04: 1Mentions · 2026-04-06: 4Mentions · 2026-04-07: 1Mentions · 2026-04-08: 1Patch / Workaround · 2026-04-06: 1Patch / Workaround · 2026-04-08: 1Technical Details · 2026-04-04: 1Technical Details · 2026-04-06: 404-0404-0604-0704-08
Signal classification3 categories
Disclosure
457.1%
Patch
228.6%
General
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-041
Disclosure1
2026-04-064
Disclosure3Patch1
2026-04-071
General1
2026-04-081
Patch1
Full discourse7 posts
  • Gray Hats@the_yellow_fall
    Disclosure

    CVE-2026-34950: A critical 9.1 CVSS flaw in fast-jwt allows authentication bypass via leading whitespace. Learn how a regex error leads to algorithm confusion. #fastjwt #CVE202634950 #InfoSec #CyberSecurity #JWT #WebDev #BugBounty https://securityonline.info/fast-jwt-authentication-bypass-cve-2026-34950-whitespace/ https://t.co/0LoCxnqZ4c

    Post summary

    The post announces CVE‑2026‑34950, a critical 9.1 CVSS flaw in fast‑jwt that permits authentication bypass via leading whitespace, without evidence of exploitation or available patch.

    03093704
    12.3K followersView on X
  • Firmis Labs@FirmisLabs
    Patch

    CVE-2026-34950 · NIST 9.1/10 https://nvd.nist.gov/vuln/detail/CVE-2026-34950 ask your AI: "check if my project uses fast-jwt and if it's version 6.1.0 or below" then: "update fast-jwt to the latest version and make sure authentication still works"

    Post summary

    The message references CVE-2026-34950, provides its NIST CVSS score, and recommends upgrading fast-jwt to the latest version as a mitigation.

    1000032
    1 followersView on X
  • Firmis Labs@FirmisLabs
    General

    CVE-2026-34950 · NIST 9.1/10 https://nvd.nist.gov/vuln/detail/CVE-2026-34950

    Post summary

    The text lists the CVE identifier with its NVD link, offering no additional detail or context.

    1000031
    1 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-34950: fast-jwt has an incomplete fix f... Regex anchoring fail: leading whitespace bypasses RSA key validation, letting attackers forge JWTs with symmetric HMAC—... https://zerodaysignal.com/vulnerability/CVE-2026-34950 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post describes a flaw in fast‑jwt where whitespace in JWT headers bypasses RSA key validation, allowing forged tokens via symmetric HMAC, but no PoC, exploit, or patch information is provided.

    0000159
    204 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34950 fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, the publicKeyPemMatcher regex in fast-jwt/src/crypto.js uses a ^ anchor that is defe… https://www.cve.org/CVERecord?id=CVE-2026-34950

    Post summary

    The post announces CVE‑2026‑34950, noting a regex flaw in fast‑jwt’s public key PEM matcher, but does not provide PoC, exploit, patch, or active exploitation information.

    00000121
    57.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-34950: CRITICAL] Warning: Fast JWT 6.1.0 and earlier are vulnerable to CVE-2023-48223 exploit due to flawed implementation in publicKeyPemMatcher regex. Update for improved security.#cve,CVE-2026-34950,#cybersecurity https://cvefind.com/CVE-2026-34950

    Post summary

    Fast JWT 6.1.0 and earlier are vulnerable due to a regex flaw (CVE-2023-48223); the post urges an update to mitigate the risk.

    0000063
    619 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    The `fast-jwt` library has an incomplete fix for a JWT algorithm confusion vulnerability (CVE-2026-34950), potentially leading to authentication bypass. Review `fast-jwt` usage for #JWT #AuthBypass #infosec risks. https://www.pulsepatch.io/posts/cve-2026-34950-fast-jwt-algorithm-confusion-incomplete-fix

    Post summary

    The post announces that fast-jwt’s fix for CVE‑2026‑34950 is incomplete, potentially allowing an authentication bypass through algorithm confusion.

    0000048
    11 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnearformfast-jwt-node.js-

Explore more