<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T16:55:04.726656+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-281088</id>
    <title>EUVD-2026-281088</title>
    <updated>2026-10-08T16:55:04.773153+00:00</updated>
    <content>EUVD-2026-281088</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-281088"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35042</id>
    <title>fkie_cve-2026-35042</title>
    <updated>2026-10-08T16:55:04.773195+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, fast-jwt does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that fast-jwt does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-35042"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hm7r-c7qw-ghp6</id>
    <title>GHSA-hm7r-c7qw-ghp6 — fast-jwt accepts unknown `crit` header extensions (RFC 7515 violation)</title>
    <updated>2026-10-08T16:55:04.773232+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: fast-jwt</p>
<p>## Summary</p>
<p>`fast-jwt` does not validate the `crit` (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a `crit` array listing extensions that `fast-jwt` does not understand, the library accepts the token instead of rejecting it. This violates the **MUST** requirement in the RFC.</p>
<p>---</p>
<p>## RFC Requirement</p>
<p>RFC 7515 §4.1.11:</p>
<p>&gt; If any of the listed extension Header Parameters are **not understood
&gt; and supported** by the recipient, then the **JWS is invalid**.</p>
<p>---</p>
<p>## Proof of Concept</p>
<p>```javascript
const { createSigner, createVerifier } = require("fast-jwt"); // v3.3.3</p>
<p>const signer = createSigner({ key: "secret", algorithm: "HS256" });
const token = signer({
  sub: "attacker",
  role: "admin",
  header: { crit: ["x-custom-policy"], "x-custom-policy": "require-mfa" },
});</p>
<p>// Should REJECT — x-custom-policy is not understood
const verifier = createVerifier({ key: "secret", algorithms: ["HS256"] });
try {
  const result = verifier(token);
  console.log("ACCEPTED:", result);
  // Output: ACCEPTED: { sub: 'attacker', role: 'admin' }
} catch (e) {
  console.log("REJECTED:", e.message);
}
```</p>
<p>**Expected:** Error — unsupported critical extension
**Actual:** Token accepted.</p>
<p>### Comparison</p>
<p>```javascript
// jose (panva) v4+ — correctly rejects
const jose = require("jose");
await jose.jwtVerify(token, new TextEncoder().encode("secret"));
// throws: Extension Header Parameter "x-custom-policy" is not recognized
```</p>
<p>---</p>
<p>## Impact</p>
<p>- **Split-brain veri…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hm7r-c7qw-ghp6"/>
  </entry>
</feed>
