JWT attacks, explained

Most JWT vulnerabilities are verifier bugs, not crypto breaks. The classes every implementation must survive:

  • alg:none — the unsecured-token header that turns verification off entirely if the library honors it.
  • Algorithm confusion — an RS256 public key reused as an HS256 secret, letting anyone who knows the public key forge tokens.
  • Embedded key attacks — a token that helpfully ships its own jwk, jku or x5u, asking the verifier to trust the attacker's key.
  • kid injection — key-ID values crafted as path traversal or SQL.
  • Weak HMAC secrets — HS256 with a guessable secret falls to offline brute force.

The article walks each attack with real token examples you can open in the debugger — which itself refuses to verify with a mismatched algorithm family, precisely because of these attacks.