Skip to content
#

algorithm-confusion

Here are 3 public repositories matching this topic...

Language: All
Filter by language

A comprehensive JWT attack CLI covering every major vulnerability class — from alg:none bypass to RS256→HS256 algorithm confusion, HMAC secret bruteforce, kid header injection (SQLi + path traversal), jku/x5u spoofing with built-in JWKS server, and full token forgery. Built for bug bounty hunters and red teamers.

  • Updated Apr 14, 2026
  • Python

Improve this page

Add a description, image, and links to the algorithm-confusion topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the algorithm-confusion topic, visit your repo's landing page and select "manage topics."

Learn more