<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T19:30:33.017675+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-384877</id>
    <title>EUVD-2026-384877</title>
    <updated>2026-10-09T19:30:33.062968+00:00</updated>
    <content>EUVD-2026-384877</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-384877"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-107723</id>
    <title>fkie_cve-2026-107723</title>
    <updated>2026-10-09T19:30:33.063012+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.0, fast-jwt createVerifier accepts a validly signed JWT whose payload is a JSON array because src/decoder.js checks that the payload is an object but does not reject arrays. The claim validator loop then finds no named exp, nbf, iss, aud, sub, jti, or nonce properties and silently skips those configured checks, returning the array as a successfully verified payload. An attacker who can produce or influence a validly signed token may bypass expiry, issuer, audience, subject, revocation, and replay protections. The opt-in requiredClaims option can block missing claims, and signature verification itself is not bypassed. This issue is fixed in version 6.3.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-107723"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5hjw-83fp-phq9</id>
    <title>GHSA-5hjw-83fp-phq9 — fast-jwt : Silent claim-validator bypass when JWT payload is a JSON array</title>
    <updated>2026-10-09T19:30:33.063051+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: fast-jwt</p>
<p>### Summary
 `fast-jwt`'s `createVerifier` silently skips **all** configured claim validators (`exp`, `nbf`, `iss`, `aud`, `sub`, `jti`, `nonce`) when a validly-signed JWT carries a JSON array as its payload instead of an object. The verifier reports success while having enforced only the signature. This breaks the library's documented `allowedIss` / `allowedAud` / `allowedSub` / expiry / replay-protection guarantees and violates RFC 7519 §7.2 step 10, which requires the JWT Claims Set to be a JSON object.</p>
<p>### Details
The decoder validates the **header** is a non-array object but the **payload** check is missing the `Array.isArray` guard:</p>
<p>```javascript
  // src/decoder.js:49 — header check (correct)
  if (!header || typeof header !== 'object' || Array.isArray(header)) {
    throw new TokenError(TokenError.codes.malformed, 'The token header is not a valid JSON object.')
  }</p>
<p>// src/decoder.js:65 — payload check (vulnerable)
  if (!payload || typeof payload !== 'object') {     // typeof [] === 'object'
    throw new TokenError(TokenError.codes.invalidPayload, 'The payload must be an object', { payload })
  }</p>
<p>Because typeof [] === 'object' in JavaScript, an array payload passes the decoder.</p>
<p>In the verifier's validator loop, every check is short-circuited by an in-test that is always false for an array (arrays have only
  numeric indices and length):</p>
<p>// src/verifier.js:304-323
  for (const { type, claim, allowed, array, modifier, greater, errorCode, errorVerb } of…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5hjw-83fp-phq9"/>
  </entry>
</feed>
