CVE Explorer
CVE-2026-35040
fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.1, using certain modifiers on RegExp objects in the allowedAud, allowedIss, allowedSub, allowedJti, or allowedNonce options in verify functions can cause certain unintended behaviours. This is because some modifiers are stateful and will cause failures in every second verification attempt regardless of the validity of the token provided. Such modifiers are /g (global matching) and /y (sticky matching). This does NOT allow i
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-697","description":"CWE-697: Incorrect Comparison","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:74f99813a906764016d98b5f05f9cb8a17393484136223289b29db2b930efe48 · sha256:696e805b47cf275d… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-440","description":"CWE-440: Expected Behavior Violation","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:74f99813a906764016d98b5f05f9cb8a17393484136223289b29db2b930efe48 · sha256:696e805b47cf275d… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"product":"fast-jwt","vendor":"nearform","versions":[{"status":"affected","version":"< 6.2.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:74f99813a906764016d98b5f05f9cb8a17393484136223289b29db2b930efe48 · sha256:696e805b47cf275d… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:74f99813a906764016d98b5f05f9cb8a17393484136223289b29db2b930efe48 · sha256:696e805b47cf275d… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-697","description":"CWE-697: Incorrect Comparison","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:74f99813a906764016d98b5f05f9cb8a17393484136223289b29db2b930efe48 · sha256:696e805b47cf275d… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-440","description":"CWE-440: Expected Behavior Violation","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:74f99813a906764016d98b5f05f9cb8a17393484136223289b29db2b930efe48 · sha256:696e805b47cf275d… · /containers/cna/problemTypes/1/descriptions/0
Source references
4 source assertions{"name":"https://github.com/nearform/fast-jwt/commit/18d25904e4617e8753526d1b3ab5a2cccdea726a","tags":["x_refsource_MISC"],"url":"https://github.com/nearform/fast-jwt/commit/18d25904e4617e8753526d1b3ab5a2cccdea726a"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:74f99813a906764016d98b5f05f9cb8a17393484136223289b29db2b930efe48 · sha256:696e805b47cf275d… · /containers/cna/references/2
{"name":"https://github.com/nearform/fast-jwt/pull/593","tags":["x_refsource_MISC"],"url":"https://github.com/nearform/fast-jwt/pull/593"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:74f99813a906764016d98b5f05f9cb8a17393484136223289b29db2b930efe48 · sha256:696e805b47cf275d… · /containers/cna/references/1
{"name":"https://github.com/nearform/fast-jwt/releases/tag/v6.2.1","tags":["x_refsource_MISC"],"url":"https://github.com/nearform/fast-jwt/releases/tag/v6.2.1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:74f99813a906764016d98b5f05f9cb8a17393484136223289b29db2b930efe48 · sha256:696e805b47cf275d… · /containers/cna/references/3
{"name":"https://github.com/nearform/fast-jwt/security/advisories/GHSA-3j8v-cgw4-2g6q","tags":["x_refsource_CONFIRM"],"url":"https://github.com/nearform/fast-jwt/security/advisories/GHSA-3j8v-cgw4-2g6q"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:74f99813a906764016d98b5f05f9cb8a17393484136223289b29db2b930efe48 · sha256:696e805b47cf275d… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.