Skip to content
#

jwt-attacks

Here are 9 public repositories matching this topic...

A comprehensive JWT attack CLI covering every major vulnerability class — from alg:none bypass to RS256→HS256 algorithm confusion, HMAC secret bruteforce, kid header injection (SQLi + path traversal), jku/x5u spoofing with built-in JWKS server, and full token forgery. Built for bug bounty hunters and red teamers.

  • Updated Aug 2, 2026
  • Python

Browser-based JWT/JWS forgery lab — HS256, RS256, ES256, and alg:none side by side, with real WebCrypto signing, a verifier-policy panel that flips between correct and vulnerable, and alg:none and HS/RS key-confusion forgeries that the vulnerable verifier accepts and the correct one rejects

  • Updated Oct 10, 2026
  • TypeScript

Add this topic to your repo

To associate your repository with the jwt-attacks topic, visit your repo's landing page and select "manage topics."

Learn more