Exploit for jwt_tool CVE-2015-2951 CVE-2016-10555 CVE-2018-0114 CVE-2019-20933 CVE-2020-28042 CVE-2020-28637 C

JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values

Published 10 Sep 2026Updated 10 Sep 20267 sources
CVSS 9.8 PoC CANDIDATE

What happened

JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values

Affected versions

Unknown product: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references