CVE-2026-107723 - fast-jwt : Silent claim-validator bypass when JWT payload is a JSON array
CVE ID :CVE-2026-107723 Published : Oct. 8, 2026, 10:17 p.m. | 1 hour, 12 minutes ago Description :fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.0, fast-jwt createVerifier accepts a validly signed JWT whose payload is a JSON array because src/decoder.js checks that...