Description
Decoding a JWT without verifying its signature can cause the server to accept a forged token. Without verification, the server cannot establish the token's integrity or authenticity, which can lead to authentication bypass or privilege escalation.
Potential impact
- An attacker may create a token that bypasses authentication.
- Forged claims may grant access as a user with greater privileges.
- Trusting an unverified token may expose sensitive data.
Remediation
- Verify the signature before using a JWT for authentication or authorization.
- Check that verification remains enabled in decoding options and library configuration.
- Protect the trusted signing or verification key.
- Use a maintained JWT library, and validate the allowed algorithm, issuer, audience and expiration conditions required by your service.
Examples
These excerpts compare the signature-verification option in jwt-simple. Token extraction from the Authorization header and key-configuration validation are omitted. For a standard Bearer header, remove the prefix and pass only the JWT string.
Before
const jwt = require('jwt-simple');
const secret = process.env.JWT_SECRET;
app.get('/profile', (req, res) => {
const token = req.headers.authorization;
// ⚠️ Decode without verifying the signature
const decoded = jwt.decode(token, secret, true);
res.json({ user: decoded.username });
});
After
const jwt = require('jwt-simple');
const secret = process.env.JWT_SECRET;
app.get('/profile', (req, res) => {
const token = req.headers.authorization;
try {
// ✅ Verify the signature
const decoded = jwt.decode(token, secret, false); // or omit the noVerify argument
res.json({ user: decoded.username });
} catch (error) {
res.status(401).json({ error: 'Unauthorized. Invalid token.' });
}
});
The third argument is noVerify: passing true skips verification and can allow forged tokens to bypass authentication. Passing false enables signature verification, and the handler rejects failures. Separately enforce the allowed algorithm, required claims and the user's access permissions.