appsec.fyi

JWT — A Practical Guide

A curated AppSec resource library covering XSS, SQLi, SSRF, IDOR, RCE, XXE, OSINT, and more.

JWT: A Practical Guide

Curated and synthesized by . Last updated 2026-10-01. Synthesized from 108 of 108 curated resources. Browse all 108 JWT resources →

Problem Framing

JSON Web Tokens (JWTs) have become a ubiquitous standard for securely transmitting information between parties, particularly in authentication and authorization contexts [1][2]. Their stateless nature and self-contained structure offer significant advantages in modern distributed systems and microservices architectures [1][3]. However, the widespread adoption of JWTs has also exposed a variety of security vulnerabilities stemming from their implementation and usage. This guide aims to provide an in-depth, practitioner-focused overview of JWT security, targeting experienced application security professionals.

Core Mechanics

A JWT is a compact, URL-safe representation of claims to be transferred between two parties. It is composed of three distinct parts, separated by dots (.): a header, a payload, and a signature [4][1][2][5].

The structure is represented as HEADER.PAYLOAD.SIGNATURE, where each part is Base64URL-encoded [2]. A key characteristic is that the header and payload are encoded, not encrypted, meaning they are human-readable if decoded [6]. The signature verification process is paramount; failure to do so correctly is the root cause of many JWT vulnerabilities [11][4][2][12][13].

Notable Techniques and Vulnerabilities

JWT vulnerabilities often exploit flaws in how the signature is verified, how algorithms are handled, or how keys are managed. The following are some of the most prevalent attack vectors:

Signature Verification Flaws

The integrity of a JWT relies entirely on the signature. If this verification is skipped or implemented incorrectly, attackers can manipulate the token.

Algorithm Confusion and Key Management Issues

These attacks exploit how JWT libraries handle the selection and usage of cryptographic algorithms and keys.

Claim-Related Vulnerabilities

While the signature protects the token's integrity, flaws in how claims are processed can still lead to security issues.

Library-Specific Vulnerabilities

Various JWT libraries have had specific vulnerabilities discovered:

It's crucial to keep JWT libraries updated to the latest patched versions [59][51][57][7][53][35][52][58][48][28][54][19][24][26][60].

Detection and Prevention

Securing JWT implementations requires a multi-faceted approach focusing on robust validation, secure key management, and adherence to best practices.

Key Validation Principles

Secure Key Management

Token Lifecycle and Storage

Tooling

A variety of tools can assist in analyzing, testing, and exploiting JWT vulnerabilities:

Recent Developments

The JWT landscape continues to evolve with new vulnerabilities and attack vectors being discovered. Recent developments highlight persistent issues and emerging threats:

Where to Go Deeper

For a deeper understanding and hands-on practice with JWT vulnerabilities and attacks, the following resources are highly recommended:

Sources cited in this guide

  1. Can Snyk Detect JWT Security Issues? — snyk.io
  2. JSON Web Token Attacks and Vulnerabilities — Acunetix — acunetix.com
  3. JWT Security Guide: Best Practices & Implementation (Gupta Deepak) — guptadeepak.com
  4. Two Ways To Mess Up Your JWT Safety Net In Your Own Lab. — infosecwriteups.com
  5. Understanding JWT Security and Common Vulnerabilities (secops) — secops.group
  6. I made a full JWT hacking tutorial + testing suite — hakluke.com
  7. CVE-2026-22817: JWT Algorithm Confusion in Hono — dev.to
  8. JWT Algorithm Confusion Attack: Two Active CVEs in 2026 — tools.pinusx.com
  9. Top 3 security best practices for handling JWTs — snyk.io
  10. JWT Security Best Practices (Phase Two) — phasetwo.io
  11. Revisiting JWT Token Forgery Attack on Recent Bounty Target — infosecwriteups.com
  12. JWT Vulnerabilities List: 2026 Security Risks & Mitigation Guide (Red Sentry) — redsentry.com
  13. Vaadata: JWT vulnerabilities, common attacks and security best practices — vaadata.com
  14. The Ultimate Guide to JWT Vulnerabilities and Attacks — pentesterlab.com
  15. OWASP WSTG: Testing JSON Web Tokens — owasp.org
  16. Insecure JSON Web Tokens (The Hacker Recipes) — thehacker.recipes
  17. Known Exploits and Attacks (jwt_tool Wiki) — github.com
  18. JWT Authentication Bypass Using alg:none - CTF Writeup — medium.com
  19. JWT Algorithm Confusion Attacks: CVE-2026-22817 Fix Guide — dev.to
  20. PortSwigger KB: JWT none algorithm supported — portswigger.net
  21. tuhin1729 Bug Bounty Methodology: JWT — github.com
  22. PayloadsAllTheThings: JSON Web Token — github.com
  23. How JWT Libraries Block Algorithm Confusion: Code Review Lessons — pentesterlab.com
  24. CVE-2024-33663: Python-jose Algorithm Confusion — sentinelone.com
  25. WorkOS: JWT algorithm confusion attacks explained — workos.com
  26. PentesterLab: Another JWT Algorithm Confusion Vulnerability (CVE-2024-54150) — pentesterlab.com
  27. Algorithm confusion attacks | Web Security Academy — portswigger.net
  28. Python-JOSE Security Risk: CVE-2024-33663 Explained — ethicalhacking.uk
  29. Cracking JWT Keys - Authentication Lab — authlab.digi.ninja
  30. Brute Forcing HS256 is Possible — auth0.com
  31. brendan-rius/c-jwt-cracker: JWT brute-force cracker in C — github.com
  32. mazen160/jwt-pwn: Security testing scripts for JWT — github.com
  33. jwt_tool Attack Methodology wiki — github.com
  34. JWT attacks | Web Security Academy — portswigger.net
  35. CVE-2026-23993: JWT Authentication Bypass in HarbourJwt via Unknown alg — pentesterlab.com
  36. JWT authentication bypass via kid header path traversal (siunam) — siunam321.github.io
  37. JWT Signature Bypass via kid Path Traversal — invicti.com
  38. JWT Signature Bypass via kid SQL injection — invicti.com
  39. JWT Forgery via unvalidated jku parameter (Invicti) — invicti.com
  40. JWT Signature Bypass via unvalidated jku parameter — invicti.com
  41. Lab: JWT authentication bypass via jku header injection — portswigger.net
  42. KathanP19/HowToHunt: JWT — github.com
  43. dr34mhacks/jwtauditor: JWT Auditor – Analyze, break, and understand your tokens like a pro. — github.com
  44. Intigriti: Exploiting JWT vulnerabilities — advanced exploitation guide — intigriti.com
  45. PortSwigger jwt-editor: Burp Suite extension for editing and signing JWTs — github.com
  46. HackerOne: Argo CD JWT audience claim not verified — hackerone.com
  47. JWT (Json Web Token) Audience aud versus Client_Id - What's the difference? — stackoverflow.com
  48. CVE-2024-53861: PyJWT Issuer Field Partial Match — vulert.com
  49. JWT Token Lifecycle: Expiration, Refresh, and Revocation — skycloak.io
  50. These are the security issues with JWT — scip.ch
  51. CVE-2026-32597: PyJWT Information Disclosure Vulnerability — sentinelone.com
  52. CVE-2025-45768: PyJWT Information Disclosure Vulnerability — sentinelone.com
  53. Proof of Concept for CVE-2026-29000 (pac4j-jwt) — github.com
  54. CVE-2026-29000: Authentication Bypass in pac4j-jwt — arcticwolf.com
  55. Severe Security Flaw Found in jsonwebtoken Library — thehackernews.com
  56. Auth0: Critical vulnerabilities in JSON Web Token libraries — auth0.com
  57. CVE-2026-34950 fast-jwt: Incomplete Fix for CVE-2023-48223 — endorlabs.com
  58. python-jwt token forgery CVE-2022-39227 — github.com
  59. JWTweak v2.1: A Guided, Offline Toolkit for Modern JWT Attacks — infosecwriteups.com
  60. ticarpi/jwt_tool: A toolkit for testing, tweaking and cracking JSON Web Tokens — github.com
  61. JWT Security Best Practices for 2025 (JWT.app) — jwt.app
  62. Curity: JWT Security Best Practices — curity.io
  63. Lab: JWT authentication bypass via weak signing key — portswigger.net
  64. Where to Store the JSON Web Token (JWT)? — medium.com
  65. jwt-hack: JSON Web Token Hack Toolkit (GitHub) — github.com
  66. Hacker Tools: JWT_Tool — intigriti.com
  67. Working with JWTs in Burp Suite — portswigger.net
  68. JSON Web Token Attacker Burp extension — portswigger.net
  69. JWT Scanner Burp extension — portswigger.net
  70. Introducing CookieMonster: a tool for breaking stateless authentication — ian.sh
  71. draft-ietf-oauth-rfc8725bis: JSON Web Token Best Current Practices — datatracker.ietf.org
  72. RFC 8725 - JSON Web Token Best Current Practices — datatracker.ietf.org
  73. RFC 8725: JSON Web Token Best Current Practices — ietf.org
  74. JWT Pentest Book (six2dez) — pentestbook.six2dez.com
  75. November CTF Challenge: Exploiting JWT vulnerabilities to achieve RCE — intigriti.com
📚 This guide is synthesized from the full text of resources curated in the JWT library, and refreshed as new material is added.