Web Hack List

Preliminary research

Token Time Bomb: Evaluating JWT Implementations for Vulnerability Discovery

AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.

JSON Web Token libraries expose a flexible surface - algorithm negotiation, nested signing and encryption, compression - that implementations handle inconsistently. JWTeemo models the token grammar in an extended BNF for feedback-guided generation, using parsing discrepancies and resource exhaustion as oracles. Across 43 libraries in 10 languages it found 31 flaws, 20 given CVEs, including authentication bypass in Kubernetes and denial of service in Apache James.

Record

Researcher
Jingcheng Yang, Enze Wang, Jianjun Chen, Qi Wang, Yuheng Zhang, Haixin Duan, Wei Xie and Baosheng Wang
Published by
ndss-symposium.org
Format
Whitepaper
Topic
Identity

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Jingcheng Yang, Enze Wang, Jianjun Chen, Qi Wang, Yuheng Zhang, Haixin Duan, Wei Xie and Baosheng Wang, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .