<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 19:40:28 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-281088</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-281088</link>
      <description>EUVD-2026-281088</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-281088</guid>
    </item>
    <item>
      <title>fkie_cve-2026-35042</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35042</link>
      <description>&lt;p&gt;fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, fast-jwt does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that fast-jwt does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, fast-jwt does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that fast-jwt does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-35042</guid>
    </item>
    <item>
      <title>GHSA-hm7r-c7qw-ghp6 — fast-jwt accepts unknown `crit` header extensions (RFC 7515 violation)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hm7r-c7qw-ghp6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: fast-jwt&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`fast-jwt` does not validate the `crit` (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a `crit` array listing extensions that `fast-jwt` does not understand, the library accepts the token instead of rejecting it. This violates the **MUST** requirement in the RFC.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## RFC Requirement&lt;/p&gt;
&lt;p&gt;RFC 7515 §4.1.11:&lt;/p&gt;
&lt;p&gt;&amp;gt; If any of the listed extension Header Parameters are **not understood
&amp;gt; and supported** by the recipient, then the **JWS is invalid**.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;```javascript
const { createSigner, createVerifier } = require(&amp;#34;fast-jwt&amp;#34;); // v3.3.3&lt;/p&gt;
&lt;p&gt;const signer = createSigner({ key: &amp;#34;secret&amp;#34;, algorithm: &amp;#34;HS256&amp;#34; });
const token = signer({
  sub: &amp;#34;attacker&amp;#34;,
  role: &amp;#34;admin&amp;#34;,
  header: { crit: [&amp;#34;x-custom-policy&amp;#34;], &amp;#34;x-custom-policy&amp;#34;: &amp;#34;require-mfa&amp;#34; },
});&lt;/p&gt;
&lt;p&gt;// Should REJECT — x-custom-policy is not understood
const verifier = createVerifier({ key: &amp;#34;secret&amp;#34;, algorithms: [&amp;#34;HS256&amp;#34;] });
try {
  const result = verifier(token);
  console.log(&amp;#34;ACCEPTED:&amp;#34;, result);
  // Output: ACCEPTED: { sub: &amp;#39;attacker&amp;#39;, role: &amp;#39;admin&amp;#39; }
} catch (e) {
  console.log(&amp;#34;REJECTED:&amp;#34;, e.message);
}
```&lt;/p&gt;
&lt;p&gt;**Expected:** Error — unsupported critical extension
**Actual:** Token accepted.&lt;/p&gt;
&lt;p&gt;### Comparison&lt;/p&gt;
&lt;p&gt;```javascript
// jose (panva) v4+ — correctly rejects
const jose = require(&amp;#34;jose&amp;#34;);
await jose.jwtVerify(token, new TextEncoder().encode(&amp;#34;secret&amp;#34;));
// throws: Extension Header Parameter &amp;#34;x-custom-policy&amp;#34; is not recognized
```&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;- **Split-brain veri…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: fast-jwt&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`fast-jwt` does not validate the `crit` (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a `crit` array listing extensions that `fast-jwt` does not understand, the library accepts the token instead of rejecting it. This violates the **MUST** requirement in the RFC.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## RFC Requirement&lt;/p&gt;
&lt;p&gt;RFC 7515 §4.1.11:&lt;/p&gt;
&lt;p&gt;&amp;gt; If any of the listed extension Header Parameters are **not understood
&amp;gt; and supported** by the recipient, then the **JWS is invalid**.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;```javascript
const { createSigner, createVerifier } = require(&amp;#34;fast-jwt&amp;#34;); // v3.3.3&lt;/p&gt;
&lt;p&gt;const signer = createSigner({ key: &amp;#34;secret&amp;#34;, algorithm: &amp;#34;HS256&amp;#34; });
const token = signer({
  sub: &amp;#34;attacker&amp;#34;,
  role: &amp;#34;admin&amp;#34;,
  header: { crit: [&amp;#34;x-custom-policy&amp;#34;], &amp;#34;x-custom-policy&amp;#34;: &amp;#34;require-mfa&amp;#34; },
});&lt;/p&gt;
&lt;p&gt;// Should REJECT — x-custom-policy is not understood
const verifier = createVerifier({ key: &amp;#34;secret&amp;#34;, algorithms: [&amp;#34;HS256&amp;#34;] });
try {
  const result = verifier(token);
  console.log(&amp;#34;ACCEPTED:&amp;#34;, result);
  // Output: ACCEPTED: { sub: &amp;#39;attacker&amp;#39;, role: &amp;#39;admin&amp;#39; }
} catch (e) {
  console.log(&amp;#34;REJECTED:&amp;#34;, e.message);
}
```&lt;/p&gt;
&lt;p&gt;**Expected:** Error — unsupported critical extension
**Actual:** Token accepted.&lt;/p&gt;
&lt;p&gt;### Comparison&lt;/p&gt;
&lt;p&gt;```javascript
// jose (panva) v4+ — correctly rejects
const jose = require(&amp;#34;jose&amp;#34;);
await jose.jwtVerify(token, new TextEncoder().encode(&amp;#34;secret&amp;#34;));
// throws: Extension Header Parameter &amp;#34;x-custom-policy&amp;#34; is not recognized
```&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;- **Split-brain veri…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hm7r-c7qw-ghp6</guid>
    </item>
  </channel>
</rss>
