CVE-2026-107722 - fast-jwt: Incomplete patch of CVE-2026-34950: Non-whitespace key-prefix re-enables RSA→HS256 algorithm confusion
CVE ID :CVE-2026-107722 Published : Oct. 8, 2026, 10:17 p.m. | 1 hour, 12 minutes ago Description :fast-jwt provides fast JSON Web Token (JWT) implementation. From 6.2.0 until 6.3.0, fast-jwt can misclassify RSA public-key text as an HMAC secret when the key has non-whitespace content before...