JWT Authentication Bypass and Algorithm Confusion Attacks
Server trust the token header to decide which algorithm verifies it, enabling forged credentials.
Selin Petrova
Contributing Editor
Selin Petrova is a contributing editor at Breach Authority covering features. Based in Austin, Selin has written for Breach Authority since 2017.
1 story · Austin
Server trust the token header to decide which algorithm verifies it, enabling forged credentials.