CVE-2026-107723: fast-jwt claim validation bypass via array payload
A type-confusion flaw in NearForm fast-jwt before 6.3.0 (CVSS 8.1) lets a validly signed JWT structured as a JSON array bypass exp, iss, aud and sub claim checks. It is patched in version 6.3.0.
- CVSS 8.1, CWE-1287, published October 8, 2026
- Affects fast-jwt below 6.3.0; patch released
- Public proof-of-concept exists, not in CISA KEV
- Enabling requiredClaims enforces strict verification
Read next
Security