Q: Your application uses stateless JSON Web Tokens (JWT) for authentication. During a security review, you notice the application accepts tokens with the header `{"alg": "none"}`. Why is this a catastrophic vulnerability?
A JWT consists of three parts: Header, Payload, and Signature. The Signature is what guarantees the token hasn't been tampered with.
🛠️ Production Runbook & Step-by-Step Resolution
Production Solution & Architecture
A JWT consists of three parts: Header, Payload, and Signature. The Signature is what guarantees the token hasn't been tampered with. The Header dictates what cryptographic algorithm was used to create the signature (e.g., HS256 or RS256). If an application's JWT parsing library accepts the alg: none header, an attacker can simply decode a valid JWT, change the payload data (e.g., elevating their role from user to admin), strip the signature entirely, set the algorithm to none, and send it back. The server will parse the header, see "none", decide it doesn't need to mathematically verify a signature, and grant full admin access based on the forged payload.
- Immediate Triage: A JWT consists of three parts: Header, Payload, and Signature. The Signature is what guarantees
- Run targeted verification commands before modifying configuration.
- Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.