CVE-2026-35042
fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, fast-jwt does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that fast-jwt does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS probability
- 0.15%
- CWE
- CWE-345, CWE-636
- Published
- 2026-04-06
- Last modified
- 2026-04-07
Affected products
- nearform fast-jwt
Weakness type
Related vulnerabilities
- CVE-2026-80172 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-73316 — XenForo < 2.3.13 Payment Replay via PayPal REST Payment Provider
- CVE-2026-85008 — undici vulnerable to caching and replay of unsafe HTTP method responses
- CVE-2026-85621 — LobeChat 2.2.1 Webhook Signature Verification Bypass QQ Feishu
- CVE-2026-85435 — MOOS-IvP through 24.8.1 uFldNodeBroker Unauthenticated Shore Route Enrollment
- CVE-2026-85434 — MOOS-IvP through 24.8.1 uFldShoreBroker Bridge Route Injection via Unverified Node Ping
- CVE-2026-85431 — MOOS essential-moos through 10.0.1 pMOOSBridge Unauthenticated UDP Packet Injection
- CVE-2026-85430 — MOOS essential-moos through 10.0.1 pShare Unauthenticated UDP Datagram Republishing