What happened
JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values
Affected versions
Unknown product: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
SploitusJWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload valuesKitPloit2026-09-10T07:59:46Candidatekitploit.comJWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload valuesen2026-09-10T07:59:46CandidatePoC-in-GitHub · CircuitSoul/poc-cve-2016-10555Change the algorithm RS256(asymmetric) to HS256(symmetric) - POC (CVE-2016-10555)★ 1CircuitSoul2021-06-14CandidatePoC-in-GitHub · scent2d/PoC-CVE-2016-10555CVE-2016-10555 PoC code★ 0scent2d2022-01-02CandidatePoC-in-GitHub · z-bool/Venom-JWT针对JWT渗透开发的漏洞验证/密钥爆破工具,针对CVE-2015-9235/空白密钥/未验证签名攻击/CVE-2016-10555/CVE-2018-0114/CVE-2020-28042的结果生成用于FUZZ,也可使用字典/字符枚举(包括JJWT)的方式进行爆破(JWT Crack)★ 288z-bool2025-01-27CandidateSource timeline
Discovered through SploitusView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.