<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>appsec.fyi — JSON Web Tokens (JWT)</title>
  <link>https://appsec.fyi/jwt.html</link>
  <description>Curated JSON Web Tokens (JWT) resources from appsec.fyi</description>
  <language>en-us</language>
  <atom:link href="https://appsec.fyi/feeds/jwt.xml" rel="self" type="application/rss+xml"/>
  <lastBuildDate>Fri, 10 Apr 2026 21:32:17 +0000</lastBuildDate>
  <managingEditor>carl@chs.us (Carl Sampson)</managingEditor>
  <item>
    <title>PortSwigger KB: JWT none algorithm supported</title>
    <link>https://portswigger.net/kb/issues/00200901_jwt-none-algorithm-supported</link>
    <guid isPermaLink="true">https://portswigger.net/kb/issues/00200901_jwt-none-algorithm-supported</guid>
    <description>PortSwigger KB: JWT none algorithm supported</description>
    <category>JSON Web Tokens (JWT)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:47 +0000</pubDate>
  </item>
  <item>
    <title>Intigriti: Exploiting JWT vulnerabilities — advanced exploitation guide</title>
    <link>https://www.intigriti.com/researchers/blog/hacking-tools/exploiting-jwt-vulnerabilities</link>
    <guid isPermaLink="true">https://www.intigriti.com/researchers/blog/hacking-tools/exploiting-jwt-vulnerabilities</guid>
    <description>Intigriti: Exploiting JWT vulnerabilities — advanced exploitation guide</description>
    <category>JSON Web Tokens (JWT)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:46 +0000</pubDate>
  </item>
  <item>
    <title>Vaadata: JWT vulnerabilities, common attacks and security best practices</title>
    <link>https://www.vaadata.com/blog/jwt-json-web-token-vulnerabilities-common-attacks-and-security-best-practices/</link>
    <guid isPermaLink="true">https://www.vaadata.com/blog/jwt-json-web-token-vulnerabilities-common-attacks-and-security-best-practices/</guid>
    <description>Vaadata: JWT vulnerabilities, common attacks and security best practices</description>
    <category>JSON Web Tokens (JWT)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:45 +0000</pubDate>
  </item>
  <item>
    <title>WorkOS: JWT algorithm confusion attacks explained</title>
    <link>https://workos.com/blog/jwt-algorithm-confusion-attacks</link>
    <guid isPermaLink="true">https://workos.com/blog/jwt-algorithm-confusion-attacks</guid>
    <description>WorkOS: JWT algorithm confusion attacks explained</description>
    <category>JSON Web Tokens (JWT)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:45 +0000</pubDate>
  </item>
  <item>
    <title>PentesterLab: Another JWT Algorithm Confusion Vulnerability (CVE-2024-54150)</title>
    <link>https://pentesterlab.com/blog/another-jwt-algorithm-confusion-cve-2024-54150</link>
    <guid isPermaLink="true">https://pentesterlab.com/blog/another-jwt-algorithm-confusion-cve-2024-54150</guid>
    <description>PentesterLab: Another JWT Algorithm Confusion Vulnerability (CVE-2024-54150)</description>
    <category>JSON Web Tokens (JWT)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:44 +0000</pubDate>
  </item>
  <item>
    <title>Curity: JWT Security Best Practices</title>
    <link>https://curity.io/resources/learn/jwt-best-practices/</link>
    <guid isPermaLink="true">https://curity.io/resources/learn/jwt-best-practices/</guid>
    <description>Curity: JWT Security Best Practices</description>
    <category>JSON Web Tokens (JWT)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:43 +0000</pubDate>
  </item>
  <item>
    <title>RFC 8725: JSON Web Token Best Current Practices</title>
    <link>https://www.ietf.org/archive/id/draft-sheffer-oauth-rfc8725bis-01.html</link>
    <guid isPermaLink="true">https://www.ietf.org/archive/id/draft-sheffer-oauth-rfc8725bis-01.html</guid>
    <description>RFC 8725: JSON Web Token Best Current Practices</description>
    <category>JSON Web Tokens (JWT)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:42 +0000</pubDate>
  </item>
  <item>
    <title>Auth0: Critical vulnerabilities in JSON Web Token libraries</title>
    <link>https://auth0.com/blog/critical-vulnerabilities-in-json-web-token-libraries/</link>
    <guid isPermaLink="true">https://auth0.com/blog/critical-vulnerabilities-in-json-web-token-libraries/</guid>
    <description>Auth0: Critical vulnerabilities in JSON Web Token libraries</description>
    <category>JSON Web Tokens (JWT)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:42 +0000</pubDate>
  </item>
  <item>
    <title>OWASP WSTG: Testing JSON Web Tokens</title>
    <link>https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/06-Session_Management_Testing/10-Testing_JSON_Web_Tokens</link>
    <guid isPermaLink="true">https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/06-Session_Management_Testing/10-Testing_JSON_Web_Tokens</guid>
    <description>OWASP WSTG: Testing JSON Web Tokens</description>
    <category>JSON Web Tokens (JWT)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:41 +0000</pubDate>
  </item>
  <item>
    <title>OWASP JSON Web Token for Java Cheat Sheet</title>
    <link>https://cheatsheetseries.owasp.org/cheatsheets/JSON_Web_Token_for_Java_Cheat_Sheet.html</link>
    <guid isPermaLink="true">https://cheatsheetseries.owasp.org/cheatsheets/JSON_Web_Token_for_Java_Cheat_Sheet.html</guid>
    <description>OWASP JSON Web Token for Java Cheat Sheet</description>
    <category>JSON Web Tokens (JWT)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:40 +0000</pubDate>
  </item>
  <item>
    <title>KathanP19/HowToHunt: JWT</title>
    <link>https://github.com/KathanP19/HowToHunt/blob/master/JWT/JWT.md</link>
    <guid isPermaLink="true">https://github.com/KathanP19/HowToHunt/blob/master/JWT/JWT.md</guid>
    <description>KathanP19/HowToHunt: JWT</description>
    <category>JSON Web Tokens (JWT)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:39 +0000</pubDate>
  </item>
  <item>
    <title>tuhin1729 Bug Bounty Methodology: JWT</title>
    <link>https://github.com/tuhin1729/Bug-Bounty-Methodology/blob/main/JWT.md</link>
    <guid isPermaLink="true">https://github.com/tuhin1729/Bug-Bounty-Methodology/blob/main/JWT.md</guid>
    <description>tuhin1729 Bug Bounty Methodology: JWT</description>
    <category>JSON Web Tokens (JWT)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:39 +0000</pubDate>
  </item>
  <item>
    <title>HackTricks: JWT vulnerabilities</title>
    <link>https://book.hacktricks.xyz/pentesting-web/hacking-jwt-json-web-tokens</link>
    <guid isPermaLink="true">https://book.hacktricks.xyz/pentesting-web/hacking-jwt-json-web-tokens</guid>
    <description>HackTricks: JWT vulnerabilities</description>
    <category>JSON Web Tokens (JWT)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:38 +0000</pubDate>
  </item>
  <item>
    <title>PayloadsAllTheThings: JSON Web Token</title>
    <link>https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/JSON%20Web%20Token/README.md</link>
    <guid isPermaLink="true">https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/JSON%20Web%20Token/README.md</guid>
    <description>PayloadsAllTheThings: JSON Web Token</description>
    <category>JSON Web Tokens (JWT)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:37 +0000</pubDate>
  </item>
  <item>
    <title>DontPanicO/jwtXploiter: A tool to test the security of JSON Web Tokens</title>
    <link>https://github.com/DontPanicO/jwtXploiter</link>
    <guid isPermaLink="true">https://github.com/DontPanicO/jwtXploiter</guid>
    <description>DontPanicO/jwtXploiter: A tool to test the security of JSON Web Tokens</description>
    <category>JSON Web Tokens (JWT)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:36 +0000</pubDate>
  </item>
  <item>
    <title>brendan-rius/c-jwt-cracker: JWT brute-force cracker in C</title>
    <link>https://github.com/brendan-rius/c-jwt-cracker</link>
    <guid isPermaLink="true">https://github.com/brendan-rius/c-jwt-cracker</guid>
    <description>brendan-rius/c-jwt-cracker: JWT brute-force cracker in C</description>
    <category>JSON Web Tokens (JWT)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:35 +0000</pubDate>
  </item>
  <item>
    <title>mazen160/jwt-pwn: Security testing scripts for JWT</title>
    <link>https://github.com/mazen160/jwt-pwn</link>
    <guid isPermaLink="true">https://github.com/mazen160/jwt-pwn</guid>
    <description>mazen160/jwt-pwn: Security testing scripts for JWT</description>
    <category>JSON Web Tokens (JWT)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:34 +0000</pubDate>
  </item>
  <item>
    <title>jwt_tool Attack Methodology wiki</title>
    <link>https://github.com/ticarpi/jwt_tool/wiki/Attack-Methodology</link>
    <guid isPermaLink="true">https://github.com/ticarpi/jwt_tool/wiki/Attack-Methodology</guid>
    <description>jwt_tool Attack Methodology wiki</description>
    <category>JSON Web Tokens (JWT)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:34 +0000</pubDate>
  </item>
  <item>
    <title>ticarpi/jwt_tool: A toolkit for testing, tweaking and cracking JSON Web Tokens</title>
    <link>https://github.com/ticarpi/jwt_tool</link>
    <guid isPermaLink="true">https://github.com/ticarpi/jwt_tool</guid>
    <description>ticarpi/jwt_tool: A toolkit for testing, tweaking and cracking JSON Web Tokens</description>
    <category>JSON Web Tokens (JWT)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:33 +0000</pubDate>
  </item>
  <item>
    <title>Working with JWTs in Burp Suite</title>
    <link>https://portswigger.net/burp/documentation/desktop/testing-workflow/vulnerabilities/session-management/jwts</link>
    <guid isPermaLink="true">https://portswigger.net/burp/documentation/desktop/testing-workflow/vulnerabilities/session-management/jwts</guid>
    <description>Working with JWTs in Burp Suite</description>
    <category>JSON Web Tokens (JWT)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:32 +0000</pubDate>
  </item>
  <item>
    <title>JSON Web Token Attacker Burp extension</title>
    <link>https://portswigger.net/bappstore/82d6c60490b540369d6d5d01822bdf61</link>
    <guid isPermaLink="true">https://portswigger.net/bappstore/82d6c60490b540369d6d5d01822bdf61</guid>
    <description>JSON Web Token Attacker Burp extension</description>
    <category>JSON Web Tokens (JWT)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:32 +0000</pubDate>
  </item>
  <item>
    <title>JWT Scanner Burp extension</title>
    <link>https://portswigger.net/bappstore/be6af6a556df4423846b25080dbde88c</link>
    <guid isPermaLink="true">https://portswigger.net/bappstore/be6af6a556df4423846b25080dbde88c</guid>
    <description>JWT Scanner Burp extension</description>
    <category>JSON Web Tokens (JWT)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:31 +0000</pubDate>
  </item>
  <item>
    <title>PortSwigger jwt-editor: Burp Suite extension for editing and signing JWTs</title>
    <link>https://github.com/PortSwigger/jwt-editor</link>
    <guid isPermaLink="true">https://github.com/PortSwigger/jwt-editor</guid>
    <description>PortSwigger jwt-editor: Burp Suite extension for editing and signing JWTs</description>
    <category>JSON Web Tokens (JWT)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:30 +0000</pubDate>
  </item>
  <item>
    <title>Algorithm confusion attacks | Web Security Academy</title>
    <link>https://portswigger.net/web-security/jwt/algorithm-confusion</link>
    <guid isPermaLink="true">https://portswigger.net/web-security/jwt/algorithm-confusion</guid>
    <description>Algorithm confusion attacks | Web Security Academy</description>
    <category>JSON Web Tokens (JWT)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:29 +0000</pubDate>
  </item>
  <item>
    <title>JWT attacks | Web Security Academy</title>
    <link>https://portswigger.net/web-security/jwt</link>
    <guid isPermaLink="true">https://portswigger.net/web-security/jwt</guid>
    <description>JWT attacks | Web Security Academy</description>
    <category>JSON Web Tokens (JWT)</category>
    <pubDate>Fri, 10 Apr 2026 21:21:28 +0000</pubDate>
  </item>
</channel>
</rss>