CVE-2026-35039Disclosure(nearform / fast-jwt)

LOWCVSS 9.1 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch nearform fast-jwt systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

fast-jwt provides fast JSON Web Token (JWT) implementation. From 0.0.1 to before 6.2.0, setting up a custom cacheKeyBuilder method which does not properly create unique keys for different tokens can lead to cache collisions. This could cause tokens to be mis-identified during the verification process leading to valid tokens returning claims from different valid tokens and users being mis-identified as other users based on the wrong token. Version 6.2.0 contains a patch.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-345CWE-706CWE-1289

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fast-jwt

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-04-06)
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
fast-jwt

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-04-03: 2Mentions · 2026-04-06: 3Patch / Workaround · 2026-04-03: 1Patch / Workaround · 2026-04-06: 1Technical Details · 2026-04-03: 2Technical Details · 2026-04-06: 204-0304-06
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-032
Disclosure1Patch1
2026-04-063
Disclosure2Patch1
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-35039 fast-jwt provides fast JSON Web Token (JWT) implementation. From 0.0.1 to before 6.1.0, setting up a custom cacheKeyBuilder method which does not properly create uniq… https://www.cve.org/CVERecord?id=CVE-2026-35039

    Post summary

    The tweet announces CVE‑2026‑35039 affecting the fast-jwt library, referencing a flaw in the custom cacheKeyBuilder method, but provides no PoC, exploit, or patch details.

    00000102
    57.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-35039: CRITICAL] Ensure your cyber security with fast-jwt's improved JWT implementation. Avoid cache collision risks by setting up unique cacheKeys for tokens after 6.1.0. Stay protected!#cve,CVE-2026-35039,#cybersecurity https://cvefind.com/CVE-2026-35039

    Post summary

    The tweet highlights a critical vulnerability in fast-jwt’s JWT implementation, advises setting unique cacheKeys beginning with version 6.1.0 to mitigate cache collision risks, and effectively promotes a workaround.

    0000043
    619 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-35039: fast-jwt Affected by Cache Confu... Cache key collisions in fast-jwt's custom cacheKeyBuilder can swap user identities - authentication bypass meets privil... https://zerodaysignal.com/vulnerability/CVE-2026-35039 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces a cache key collision vulnerability in fast-jwt that permits identity swapping and privilege escalation, without mention of active exploitation or mitigation.

    0000050
    204 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    The `fast-jwt` library has a cache confusion vulnerability (CVE-2026-35039) leading to identity/authorization mixup. Review `cacheKeyBuilder` configurations. #jwt #security #nodejs https://www.pulsepatch.io/posts/cve-2026-35039-fast-jwt-cache-confusion

    Post summary

    The post announces CVE-2026-35039, a cache confusion flaw in the fast-jwt library that can cause identity and authorization mix‑ups, and recommends reviewing cacheKeyBuilder settings.

    0000046
    10 followersView on X
  • Vulert@vulert_official
    Patch

    🚨 Critical fast-jwt flaw: CVE-2026-35039 An improper caching issue could put applications at serious risk. Update now or apply the recommended workaround. 🔗 https://vulert.com/vuln-db/CVE-2026-35039 #CyberSecurity #fastjwt #CVE202635039 #Vulert https://t.co/RGeNLaDbfx

    Post summary

    The tweet announces a critical fast-jwt flaw (CVE‑2026‑35039), warns that an improper caching issue could be exploited, and urges users to update or apply a recommended workaround.

    0000035
    123 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnearformfast-jwt-node.js-

Explore more