{"id":"CVE-2026-35042","aliases":["GHSA-hm7r-c7qw-ghp6"],"url":"https://o3.security/vulnerability/CVE-2026-35042","summary":"fast-jwt accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)","details":"fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, fast-jwt does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that fast-jwt does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC.","published":"2026-04-06T17:02:12.180Z","modified":"2026-08-07T11:31:28.157812399Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"fast-jwt","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://www.rfc-editor.org/rfc/rfc7515.html#section-4.1.11"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/35xxx/CVE-2026-35042.json"},{"type":"ADVISORY","url":"https://github.com/nearform/fast-jwt/security/advisories/GHSA-hm7r-c7qw-ghp6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35042"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:31:28.157812399Z"}}