SCA: security update for fast-jwt (GHSA-ww5h-9m49-7xx4)

critical Tenable Self-Hosted Container Security Plugin ID 473967

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- fast-jwt provides fast JSON Web Token (JWT) implementation. From 6.2.0 until 6.3.0, fast-jwt can
misclassify RSA public-key text as an HMAC secret when the key has non-whitespace content before its PEM
header. In src/crypto.js, performDetectPublicKeyAlgorithms trims whitespace but publicKeyPemMatcher
remains start-anchored, so comments, control characters, zero-width characters, or wrapper text can
prevent PEM detection and reach the HMAC fallback. An attacker who knows the public key bytes can sign
arbitrary HS256 claims with that public material when HS256 is inferred or allowed, resulting in
authentication or authorization bypass. An asymmetric-only algorithm allowlist prevents the attack. This
issue is fixed in version 6.3.0. (CVE-2026-107722)

Solution

Update the fast-jwt library and its related packages to version 6.3.0 or later.

See Also

https://github.com/advisories/GHSA-ww5h-9m49-7xx4

Plugin Details

Severity: Critical

ID: 473967

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 10/9/2026

Updated: 10/9/2026

Risk Information

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-107722

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/8/2026

Vulnerability Publication Date: 10/8/2026

Reference Information

CVE: CVE-2026-107722

cwe: CWE-347