Skip to content

JSON Web Tokens (JWT) security: none algorithm, key confusion, weak secrets, and revocation

A comprehensive guide to JSON Web Token attack vectors: algorithm confusion (RS256 vs HS256), the 'none' algorithm bypass, weak HMAC secrets, and scalable token revocation.

By BugSnaps Security Research · · 8 min read

JSON Web Tokens (JWT) have become the default standard for stateless session handling and authorization in microservices and Single Page Applications. However, the flexibility of the JWT specification makes it a frequent source of critical authentication bypasses when improperly validated.

Critical JWT attack vectors uncovered in pentests

Penetration testers routinely discover high-severity flaws arising from improper library configuration and weak validation logic:

  • The 'none' algorithm exploit: backend libraries that accept `alg: 'none'` in the JWT header and skip signature verification entirely, allowing arbitrary user impersonation.
  • Algorithm confusion (RS256 vs HS256): tricking a server designed for asymmetric RS256 into validating tokens using HMAC (HS256) signed with the server's public key as the secret.
  • Weak HMAC secrets: signing tokens with simple dictionary words or short strings that can be cracked in seconds using Hashcat or John the Ripper.
  • Header parameter injection (`jku` and `kid`): manipulating the Key ID or JWKS URL in the header to point to an attacker-controlled signing key.

The stateless revocation problem

Because JWTs are stateless, revoking a compromised token before its expiration requires active architecture. Best practices mandate short-lived access tokens (5 to 15 minutes), secure HttpOnly refresh tokens, and a Redis-backed token revocation denylist for immediate termination upon logout or privilege change.

Always enforce explicit algorithm allowlists in your backend verification library (e.g., `algorithms: ['RS256']`), never trust header-specified algorithms blindly.

Run a real pentest on your app - free.

Sign in, prove you own the domain, and MyPentest maps and tests it. No credit card.