JWT vulnerabilities
HEADER.PAYLOAD.SIGNATURE
eyJhbGciOi... (header).eyJzdWIiOi... (payload).SGVsbG8sIHdv... (signature)What does each part contain?
Risky Header Parameters
Useful resouse:
Burpsuite Recommended extension:
Methodology
Signature Validation Bypass
Algorithm none Bypass
Brute Force the Signature Key
Header Injection Techniques
🔓 jwk Header Injection
jwk Header Injection🌐 jku Header Injection
jku Header Injection🗂️ kid Path Traversal
kid Path TraversalAlgorithm Confusion Attack (RS256 → HS256)
Algorithm Confusion Without Exposed Key
Last updated