Preliminary research
Token Time Bomb: Evaluating JWT Implementations for Vulnerability Discovery
AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
JSON Web Token libraries expose a flexible surface - algorithm negotiation, nested signing and encryption, compression - that implementations handle inconsistently. JWTeemo models the token grammar in an extended BNF for feedback-guided generation, using parsing discrepancies and resource exhaustion as oracles. Across 43 libraries in 10 languages it found 31 flaws, 20 given CVEs, including authentication bypass in Kubernetes and denial of service in Apache James.
Record
- Researcher
- Jingcheng Yang, Enze Wang, Jianjun Chen, Qi Wang, Yuheng Zhang, Haixin Duan, Wei Xie and Baosheng Wang
- Published by
- ndss-symposium.org
- Format
- Whitepaper
- Topic
- Identity
In the archive
Related sources
- Token Time Bomb: Evaluating JWT Implementations for Vulnerability Discovery (Slides) Whitepaper
- NDSS 2026 - Token Time Bomb: Evaluating JWT Implementations for Vulnerability Discovery
Tags
This page is the archive's own catalogue record. The research is the work of Jingcheng Yang, Enze Wang, Jianjun Chen, Qi Wang, Yuheng Zhang, Haixin Duan, Wei Xie and Baosheng Wang, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .