CVE-2026-82454: Jwt Unverified Header Algorithm

The JWT verification algorithm is dynamically populated from the unverified token header (`alg`). This allows an attacker to forge tokens using algorithm confusion (e.g., supplying HS256 signed with an asymmetric public key). Always hardcode or whitelist allowed algorithms explicitly (e.g. `algorithms: ['RS256']`).

Provally CuratedPublic repositoryHighHigh confidenceVerifiedApache-2.0JS
greprules fetch cve-2026-82454-jwt-unverified-header-algorithm --engine opengrep

Description

The JWT verification algorithm is dynamically populated from the unverified token header (`alg`). This allows an attacker to forge tokens using algorithm confusion (e.g., supplying HS256 signed with an asymmetric public key). Always hardcode or whitelist allowed algorithms explicitly (e.g. `algorithms: ['RS256']`).