logo

Whitespace Flaw Re-Opens Critical JWT “Algorithm Confusion” Bypass

ID: 085ee8ea-11b0-59cb-985b-20f22d6844f8

STIX ID: report--085ee8ea-11b0-59cb-985b-20f22d6844f8

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-04-06

Date Updated: 2026-04-23

Author: Ddos

...
...

**Executive Summary:** Security researchers disclosed two critical vulnerabilities in the fast-jwt library that enable JWT authentication bypass (algorithm confusion via a regex that fails on leading whitespace) and token cache collisions when custom cacheKeyBuilders are used; both issues carry a CVSS of 9.1, affect fast-jwt <= 6.1.0, and can be mitigated by explicitly specifying algorithms, trimming keys, and auditing configurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.