OVERVIEW CVE-2026-35040 affects fast-jwt versions prior to 6.2.1, a popular JSON Web Token implementation library. The vulnerability stems from improper handling of stateful RegExp modifiers (specifically /g for global matching and /y for sticky matching) when used in verify function options such as allowedAud, allowedIss, allowedSub, allowedJti, or allowedNonce. These modifiers introduce a state management issue causing valid tokens to be rejected in an alternating pattern—approximately 50% of legitimate authentication requests fail on every second attempt. SEVERITY This vulnerability carries a CVSS v3.1 score of 5.3 (Medium) with a network-based attack vector, low complexity, and no user interaction required. The impact is limited to availability, as the flaw does not allow attackers to bypass authentication or compromise confidentiality or integrity. The vulnerability causes denial of service conditions by rejecting legitimate tokens, potentially disrupting normal authentication workflows in affected systems. EXPLOITATION STATUS There is no evidence of active exploitation in the wild. The vulnerability is not listed on the Known Exploited Vulnerabilities catalog and remains inactive on threat intelligence hot lists. The EPSS score of 0.0009 indicates minimal probability of exploitation. Community attention is correspondingly low, and no publicly available exploit code has been reported, suggesting this remains a low-priority remediation issue despite its security implications.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.2.1CPE matchmatch criteria | cpe:2.3:a:nearform:fast-jwt:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.