fast-jwt versions before 3.3.2 improperly detect certain public-key PEM encodings when preventing JWT algorithm confusion. The publicKeyPemMatcher fails to recognize public keys using the BEGIN RSA PUBLIC KEY header. An attacker can submit an HS256 JWT signed using the target application's public RSA key; when the application verifies tokens with RS256 but does not explicitly restrict the accepted algorithm, it can accept attacker-signed arbitrary payloads.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small Node.js proof-of-concept for CVE-2023-48223, demonstrating JWT algorithm confusion in fast-jwt. The structure is straightforward: server.js implements a vulnerable Express application, sign.js forges a malicious JWT, checkAdmin.js sends the forged token to the protected endpoint, and the markdown files document setup and exploitation steps. The package metadata shows dependencies on express and fast-jwt 3.3.1. The main exploit capability is privilege escalation via JWT forgery. In server.js, the app signs normal user tokens with RS256 using ./keys/private.pem, but verifies incoming tokens with createVerifier({ key: publicKey }) and does not restrict algorithms. This allows an attacker to create an HS256 token signed with the RSA public key as if it were an HMAC secret. sign.js performs exactly that, generating a token with payload { admin: true, user: "attacker" }. checkAdmin.js then submits the forged token as a Bearer token to GET /admin. If accepted, the server returns a JSON response containing 'Welcome Admin!'. This is a real exploit PoC rather than a detector. It is operational but limited to a controlled local lab setup and hardcoded payload values. No external C2, persistence, or destructive behavior is present. The only meaningful network targets are the local HTTP endpoints on localhost:3000, especially /admin and /generateToken. The repository also references local key file paths required for the attack flow.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.