CVE-2015-9235 is an algorithm-confusion vulnerability in the Node.js jsonwebtoken module before version 4.2.2. A verifier intended to validate JWTs signed with asymmetric RSA or ECDSA algorithms can accept an attacker-supplied token signed with an HMAC algorithm. This permits misuse of an asymmetric public key as an HMAC secret and can bypass intended JWT signature verification.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository purpose: a self-contained demonstration of JWT algorithm confusion (CVE-2015-9235 style) against Node’s jsonwebtoken@4.0.0, showing how an attacker can turn an RS256-signed system into an HS256-verified system by controlling the JWT header and using the RSA public key as an HMAC secret. Key components / structure: - exploit-CVE20159235.py (Python): Main exploit script. It requests the backend’s RSA public key from /public-key, then forges a JWT with header alg=HS256 and payload role=admin (sub is configurable via --user). It computes the signature using HMAC-SHA256 with the fetched public key bytes as the HMAC key, outputting a ready-to-use forged token. - jwt-backend/ (Node/Express vulnerable service): - server.js: Generates an RSA keypair at runtime, exposes GET /public-key, issues RS256 tokens on POST /login, and protects GET /flag with requireAdmin. The vulnerability is in requireAdmin: jwt.verify(token, publicKey) is called without restricting allowed algorithms, enabling HS256 verification using the RSA public key as the symmetric secret. - flag.txt: Local flag file returned by /flag upon successful admin authorization. - jwt-frontend/ (React/Vite UI): Provides a login/register UI and a flag page that calls /flag with the stored Bearer token. The intended workflow is: register/login to get a normal token, run the Python exploit to generate an admin token, replace localStorage token with the forged JWT, then fetch /flag. Exploit capability: - Authentication bypass / privilege escalation (user→admin) by crafting a JWT that passes verification due to algorithm confusion (RS256→HS256) and key-type misuse. Notable targeting assumptions: - Backend must expose the public key and must verify JWTs without an explicit algorithm allowlist; this is specifically demonstrated with jsonwebtoken@4.0.0 behavior.
Repository purpose: a small Python proof-of-concept demonstrating JWT algorithm confusion (CVE-2015-9235) by forging a token that switches from an asymmetric algorithm (e.g., RS256) to HS256 and re-signs it using the victim application's public key as the HMAC secret. Structure: - main.py: CLI tool that reads a JWT from a file, base64-decodes header/payload, requires a 'pk' field in the payload, rewrites the header to HS256, updates an arbitrary payload key to a user-provided value, and computes a new HMAC-SHA256 signature over header.payload using pk as the secret. Outputs the forged JWT. - token.txt: example JWT containing a 'pk' claim with a PEM-like public key string. - README.md: English/French documentation, usage examples, and explanation of CVE-2015-9235 affecting jsonwebtoken (<4.2.2). - .github/workflows/pylint.yml: CI linting workflow. Exploit capabilities: - Offline JWT claim tampering (arbitrary key replacement) and token re-signing. - Produces a forged HS256 JWT intended to be accepted by vulnerable JWT verification implementations that mistakenly treat the public key as an HMAC secret. Network/endpoint behavior: - No network calls; the only direct I/O is reading a local token file and printing the resulting JWT. The relevant “target” is implicit: any service that validates JWTs with a vulnerable algorithm-selection/verification logic.
This repository is a Go-based operational exploit tool targeting JWT (JSON Web Token) vulnerabilities, including CVE-2015-9235, CVE-2016-10555, CVE-2018-0114, and CVE-2020-28042. The tool provides both command-line and interactive modes for penetration testers to generate and test JWTs against web applications. It supports multiple attack modes: modifying JWT headers (e.g., setting 'alg' to 'none'), exploiting missing signature validation, switching from RS256 to HS256, JWKS key injection, and brute-forcing JWT secrets using dictionaries or character sets. The tool can generate fuzzing dictionaries and outputs results to files for further testing. The codebase is organized into modules for command handling, JWT manipulation, brute-forcing, and utility functions. No hardcoded network endpoints are present, but several file paths are used for input/output. The exploit is mature and operational, providing practical attack payloads and automation for JWT vulnerability exploitation.
This repository provides a proof-of-concept (PoC) exploit for the JWT Key Confusion vulnerability (CVE-2015-9235). The main exploit script, 'jwt-9235.py', allows an attacker to forge a new JWT token by modifying any claim (such as 'username') and signing the token using the public key (extracted from the JWT payload) as the HMAC secret. This exploits misconfigured servers that use the HS256 algorithm and accept the public key as a symmetric secret, allowing attackers to escalate privileges or bypass authentication. The script takes as input the location of a JWT token file, the claim to modify, and the new value for that claim. If no arguments are provided, it defaults to modifying the 'username' claim in a token file named './token'. The repository also includes 'secret.py', a helper script for generating JWT tokens with a blank secret. No hardcoded network endpoints or IP addresses are present, but the attack is intended for use against web servers that use JWTs for authentication. The code is written in Python and is intended as a PoC for educational or testing purposes.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.