CVE-2026-44351Patch

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.4, a critical authentication-bypass vulnerability in fast-jwt's async key-resolver flow allows any unauthenticated attacker to forge arbitrary JWTs that are accepted as authentic. When the application's key resolver returns an empty string (''), for example via the common keys[decoded.header.kid] || '' JWKS-style fallback, fast-jwt converts it to a zero-length Buffer, hands it to crypto.createSecretKey, derives allowedAlgorithms = ['HS256','HS384','HS512'] from it, and then verifies the token's signature against an empty-key HMAC. The attacker simply computes HMAC-SHA256(key='', input='${header}.${payload}'), which Node accepts without complaint — and the verifier returns the attacker-chosen payload (sub, admin, scopes, etc.) as authentic. This vulnerability is fixed in 6.2.4.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-326CWE-1391

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-07); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-07: 1Mentions · 2026-05-13: 1Patch / Workaround · 2026-05-07: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-13: 105-0705-13
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-05-071
Patch1
2026-05-131
Disclosure1
Full discourse2 posts
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Critical - fast-jwt Authentication Bypass (CVE-2026-44351) A critical flaw in fast-jwt allows unauthenticated attackers to forge valid JWT tokens when applications use an async key resolver that returns an empty HMAC secret. By abusing the vulnerable verification flow, attackers can create arbitrary tokens with elevated privileges, leading to full authentication bypass and unauthorized access to protected resources. () 👉 Affected: fast-jwt <= 6.2.3 | Upgrade to fast-jwt 6.2.4

    Post summary

    The advisory reports a critical authentication bypass in fast‑jwt, details how attackers can forge JWTs, and recommends upgrading to version 6.2.4 to remediate the flaw.

    0002077
    237 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-44351 fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.4, a critical authentication-bypass vulnerability in fast-jwt's async key-resolver flow allow… https://www.cve.org/CVERecord?id=CVE-2026-44351

    Post summary

    CVE-2026-44351 describes a critical authentication-bypass flaw in fast-jwt versions prior to 6.2.4, with details available at the CVE record link.

    00000150
    57.5K followersView on X

Explore more