Περιγραφή
fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.4, a critical authentication-bypass vulnerability in fast-jwt-s async key-resolver flow allows any unauthenticated attacker to forge arbitrary JWTs that are accepted as authentic. When the application-s key resolver returns an empty string (--), for example via the common keys[decoded.header.kid] || -- JWKS-style fallback, fast-jwt converts it to a zero-length Buffer, hands it to crypto.createSecretKey, derives allowedAlgorithms = [-HS256-,-HS384-,-HS512-] from it, and then verifies the token-s signature against an empty-key HMAC. The attacker simply computes HMAC-SHA256(key=--, input=-${header}.${payload}-), which Node accepts without complaint — and the verifier returns the attacker-chosen payload (sub, admin, scopes, etc.) as authentic. This vulnerability is fixed in 6.2.4.
- Δημοσίευση
- 2026-05-13 20:16:22
- Επηρεαζόμενες εκδόσεις
- <6.2.4
- Τύπος
- Package
- Διάνυσμα
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N