Verification pipeline for detecting common JWT security vulnerabilities using industry-standard tools.
- jwt_tool - Comprehensive vulnerability testing
- jwt-hack - Quick security scan
- jwt-cracker - Weak secret detection (10s timeout)
docker build -t jwt-analyzer .
docker run --rm jwt-analyzer <JWT_TOKEN>
docker run --rm -e CRACK_TIMEOUT=30 jwt-analyzer <JWT_TOKEN>- JWT mistakes & breaches
- JWT critical flaws
- Real world JWT vulnerabilities
- CVE-2015-9235 - Algorithm confusion vulnerability