the.bay.news

BREAKING: CVE-2026-18500 - @fastify/jwt Key Override Authorization Bypass

DEV Community
BREAKING: CVE-2026-18500 - @fastify/jwt Key Override Authorization Bypass
CVE-2026-18500 lets @fastify/jwt before 10.2.2 override a route-specific verification key with the global secret, breaking JWT authorization-domain separation. NVD scores it 8.1 HIGH.

0 comments

Sign in to join the discussion — your thebay.events account works here.

No comments yet.