Tag
algorithm-confusion
Safeguard articles tagged "algorithm-confusion" — guides, analysis, and best practices for software supply chain and application security.
3 articles
Application Security
Secure JWT handling: algorithm confusion, expiry, and storage done right
A single unchecked `alg` header turned jsonwebtoken into a forgeable token in CVE-2015-9235 — here's how to close every hole RFC 8725 warns about.
Jul 8, 20266 min read
Vulnerability Guides
JWT Security Vulnerabilities and How to Avoid Them
JSON Web Tokens are only as safe as how you verify them. The alg:none trick, RS256-to-HS256 confusion, and weak secrets have all led to full auth bypass.
Jul 3, 20265 min read
Security
firebase/php-jwt: Verifying JWTs Without Getting Burned
firebase/php-jwt is the de facto library for encoding and decoding JSON Web Tokens in PHP. Here is how to use it correctly and avoid the algorithm-confusion trap.
Mar 18, 20256 min read
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.