VULNERABILITY OVERVIEW CVE-2026-35039 affects the fast-jwt library versions 0.0.1 through 6.1.x, impacting any application using custom cacheKeyBuilder methods that fail to generate unique keys for different tokens. The vulnerability stems from inadequate cache key generation that enables token cache collisions during JWT verification. This flaw can result in critical authentication bypass scenarios where valid tokens are incorrectly matched to cached entries, allowing attackers to assume the identity of other users or obtain unauthorized access to their claims. SEVERITY ASSESSMENT The vulnerability carries a CVSS 3.1 score of 9.1 (CRITICAL) with a network-based attack vector requiring no authentication or user interaction. The attack has low complexity and can compromise confidentiality and integrity across the entire system scope. The high impact reflects the potential for widespread user mis-identification and unauthorized claim disclosure, representing a severe authentication and authorization failure. EXPLOITATION STATUS The vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities (KEV) catalog and shows no signs of active exploitation in the wild. The EPSS score of 0.00018 indicates minimal probability of exploitation, placing it below the 0.046 percentile of all CVEs. However, organizations running fast-jwt versions prior to 6.2.0 should prioritize patching due to the critical CVSS rating and the vulnerability's fundamental impact on user authentication integrity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.1.0, < 6.1.0CPE matchmatch criteria | cpe:2.3:a:nearform:fast-jwt:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.