CVE-2026-44900: Jws Payload Without Signature Verificationcve-2026-44900-jws-payload-without-signature-verification
JWSObject.parse() is called and the payload is consumed without first calling .verify(verifier). Parsing a JWSObject only deserializes the token structure — the cryptographic signature is NOT checked until .verify() is explicitly called and its boolean result asserted. An attacker with a MITM position can substitute a crafted JWT (e.g., a forged OIDC discove