JSON Web Tokens (JWT) have become the default standard for stateless session handling and authorization in microservices and Single Page Applications. However, the flexibility of the JWT specification makes it a frequent source of critical authentication bypasses when improperly validated.
Critical JWT attack vectors uncovered in pentests
Penetration testers routinely discover high-severity flaws arising from improper library configuration and weak validation logic:
- The 'none' algorithm exploit: backend libraries that accept `alg: 'none'` in the JWT header and skip signature verification entirely, allowing arbitrary user impersonation.
- Algorithm confusion (RS256 vs HS256): tricking a server designed for asymmetric RS256 into validating tokens using HMAC (HS256) signed with the server's public key as the secret.
- Weak HMAC secrets: signing tokens with simple dictionary words or short strings that can be cracked in seconds using Hashcat or John the Ripper.
- Header parameter injection (`jku` and `kid`): manipulating the Key ID or JWKS URL in the header to point to an attacker-controlled signing key.
The stateless revocation problem
Because JWTs are stateless, revoking a compromised token before its expiration requires active architecture. Best practices mandate short-lived access tokens (5 to 15 minutes), secure HttpOnly refresh tokens, and a Redis-backed token revocation denylist for immediate termination upon logout or privilege change.
Always enforce explicit algorithm allowlists in your backend verification library (e.g., `algorithms: ['RS256']`), never trust header-specified algorithms blindly.