CVE-2026-54290: Jwt Jwk Algorithm Confusioncve-2026-54290-jwt-jwk-algorithm-confusion
The JWT signing function defaults to a symmetric algorithm (like 'HS256') and subsequently places it in the token header, but fails to check if the provided private key is an asymmetric JSON Web Key (JWK) containing its own structured 'alg' (algorithm) property. This allows for algorithm confusion attacks where an asymmetric key is mistakenly processed as a