Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsThere is no fixed version for fast-jwt.
fast-jwt is a Fast JSON Web Token implementation
Affected versions of this package are vulnerable to Not Failing Securely ('Failing Open') due to improper validation of the crit header parameter. An attacker can bypass intended authorization policies by crafting a signed token with unknown critical header parameters, which are improperly accepted and processed.