CVE-2026-82454: Jwt Unverified Header Algorithmcve-2026-82454-jwt-unverified-header-algorithm
The JWT verification algorithm is dynamically populated from the unverified token header (`alg`). This allows an attacker to forge tokens using algorithm confusion (e.g., supplying HS256 signed with an asymmetric public key). Always hardcode or whitelist allowed algorithms explicitly (e.g. `algorithms: ['RS256']`).