JWT attacks, explained
Most JWT vulnerabilities are verifier bugs, not crypto breaks. The classes every implementation must survive:
- alg:none — the unsecured-token header that turns verification off entirely if the library honors it.
- Algorithm confusion — an RS256 public key reused as an HS256 secret, letting anyone who knows the public key forge tokens.
- Embedded key attacks — a token that helpfully ships its own jwk, jku or x5u, asking the verifier to trust the attacker's key.
- kid injection — key-ID values crafted as path traversal or SQL.
- Weak HMAC secrets — HS256 with a guessable secret falls to offline brute force.
The article walks each attack with real token examples you can open in the debugger — which itself refuses to verify with a mismatched algorithm family, precisely because of these attacks.