SCA: security update for fast-jwt (GHSA-g3jj-5cmm-3hxx)

high Tenable Cloud Security Plugin ID 473951

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.2.4, fast-jwt can classify raw serialized
public JWK or JWKS JSON as an HMAC secret because src/crypto.js performDetectPublicKeyAlgorithms treats
non-PEM strings as symmetric key material. If HS256 is explicitly allowed or inferred, an attacker who
knows the exact serialized public-key bytes can use those bytes as an HMAC key and create a token
containing arbitrary claims that createVerifier accepts. Serialization ordering or whitespace differences
can prevent exploitation, and applications using supported PEM keys with an asymmetric-only algorithm
allowlist are not affected. This issue is fixed in version 6.3.0. (CVE-2026-107724)

Solution

Update the fast-jwt library and its related packages to version 6.3.0 or later.

See Also

https://github.com/advisories/GHSA-g3jj-5cmm-3hxx

Plugin Details

Severity: High

ID: 473951

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 10/9/2026

Updated: 10/9/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.46

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.1

Temporal Score: 5.3

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2026-107724

CVSS v3

Risk Factor: High

Base Score: 7.4

Temporal Score: 6.4

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/8/2026

Vulnerability Publication Date: 10/8/2026

Reference Information

CVE: CVE-2026-107724

cwe: CWE-347