JWT signature verification is disabled

JWT signature verification is disabled

Description

Disabling signature verification when decoding a JWT can cause an application to trust tokens created by an attacker. Settings such as PyJWT’s jwt.decode(..., options={"verify_signature": False}) can lead to authentication bypass or privilege escalation.

Potential impact

  • An attacker can create tokens with arbitrary user IDs, roles, or permission claims.
  • Expiration, audience, and issuer checks may also be bypassed.
  • Altering token contents may be enough to cross an authentication boundary.

Remediation

  • Do not use verify_signature=False in production code.
  • Specify the verification key and allowed algorithms in jwt.decode().
  • Also validate essential claims such as exp, iss, and aud.
  • Keep test-only decoding logic separate from production paths.

Examples

Before

python
import jwt

def bad_decode(token):
    return jwt.decode(token, options={"verify_signature": False})

After

python
import jwt

def safe_decode(token, key):
    return jwt.decode(token, key, algorithms=["HS256"], audience="api")

Explanation:

  • Before: The token signature is not verified.
  • After: The key, algorithm, and audience are specified to verify token integrity and the intended service.

References