fast-jwt: Stateful RegExp (/g or /y) causes non-deterministic allowed-claim validation (logical DoS)
Modified: 4/9/2026
package
pkg:npm/fast-jwt
fast-jwt: Stateful RegExp (/g or /y) causes non-deterministic allowed-claim validation (logical DoS)
Modified: 4/9/2026
JWT Algorithm Confusion
Modified: 11/20/2023
fast-jwt has a ReDoS when using RegExp in allowed* leading to CPU exhaustion during token verification
Modified: 4/9/2026
Fast-JWT Improperly Validates iss Claims
Modified: 3/20/2025
fast-jwt: JWT auth bypass due to empty HMAC secret accepted by async key resolver
Modified: 5/14/2026
fast-jwt accepts unknown `crit` header extensions (RFC 7515 violation)
Modified: 4/6/2026
fast-jwt: Incomplete fix for CVE-2023-48223: JWT Algorithm Confusion via Whitespace-Prefixed RSA Public Key
Modified: 4/7/2026
fast-jwt: Cache Confusion via cacheKeyBuilder Collisions Can Return Claims From a Different Token (Identity/Authorization Mixup)
Modified: 4/8/2026