A vulnerability in python-jwt versions prior to 3.3.4 allows attackers to bypass authentication by spoofing JWTs. An attacker with access to a JWT can forge its contents without knowledge of the secret key, due to improper verification logic in the library. This can lead to identity spoofing, session hijacking, or complete authentication bypass, depending on the application's use of JWTs.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a self-contained proof-of-concept and demo lab for CVE-2022-39227, a JWT claim forgery/authentication bypass issue in python-jwt versions before 3.3.4. The repo contains a vulnerable Flask application (`app.py`), an exploit driver (`attack_demo.py`), Docker artifacts (`Dockerfile`, `docker-compose.yml`) to run vulnerable and fixed environments side by side, and supporting documentation (`README.md`, `report.md`, `slides-outline.md`). Core exploit capability: the attack script logs in as a low-privileged user (`alice` / `alice123`) to obtain a legitimate JWT from `/login`, decodes the token payload, changes the `role` claim from `user` to `admin`, and constructs a crafted JSON-serialized JWS token. This forged bearer token is then sent to `/admin`. On the vulnerable dependency version (`python-jwt==3.3.3`), the library incorrectly accepts the manipulated token, allowing unauthorized access to the admin endpoint and disclosure of protected data (`Top Secret Data`). The same forged token is then tested against the fixed environment (`python-jwt==3.3.4`) on port 5001, where it is expected to be rejected. Repository structure and purpose: `app.py` implements the demo web app with hardcoded users, JWT issuance, JWT verification, and protected routes. `attack_demo.py` is the main exploit script and demonstrates end-to-end privilege escalation over HTTP. `requirements-vuln.txt` and `requirements-fixed.txt` pin vulnerable and patched library versions respectively. `Dockerfile` builds the app image using a selectable requirements file, and `docker-compose.yml` launches two containers: vulnerable on host port 5000 and fixed on host port 5001. The markdown files document the vulnerability, attack flow, and mitigation guidance. Overall, this is a legitimate exploit demonstration repository rather than malware. It is operational because it includes working exploit logic and a reproducible lab environment, but it is not heavily weaponized or generalized beyond the local demo setup.
Repository is a Python JWT security testing toolkit (“claimjumper”) rather than a single exploit for one product. It provides: (1) JWT decoding and vulnerability analysis with risk scoring (claimjumper/decoder.py, analyzer.py), (2) token forging (alg=none and HS256 with a provided secret) (forger.py), (3) multi-threaded HMAC secret brute forcing for HS256/384/512 using built-in/common secrets and optional wordlists (cracker.py plus wordlists/jwt_secrets.txt; also references a Wallarm wordlist path), (4) an “advanced_attacks” module that generates multiple CVE/pattern-based attack tokens (notably CVE-2022-39227 algorithm confusion, CVE-2018-0114 key injection, CVE-2022-21449 psychic signature, CVE-2020-28042 null signature bypass, plus kid/jku/x5u/jwks spoofing and timestamp tampering), (5) a fuzzing engine with payload libraries for path traversal, SQLi, NoSQLi, command injection, SSRF, etc. (fuzzer.py), and (6) optional live HTTP replay/testing and a playbook-style scanner using `requests` (http_tester.py) that can inject tokens into requests and look for canary/response changes; it logs to jwt_attack.log. The primary entry point is the Click-based CLI (claimjumper/cli.py) exposing commands like analyze, crack, forge/forge-none, advanced-attacks, fuzz, keygen, and full-audit. A standalone local HTML UI (jwt_analyzer.html) provides basic client-side decoding/forging guidance but does not itself perform signing. Overall purpose: generate and test malicious JWT variants against vulnerable JWT verification implementations and assist in auditing JWT configurations.
This repository provides a proof-of-concept exploit for CVE-2022-39227, a vulnerability in the 'python-jwt' library (versions < 3.3.4) where JWT signature verification is flawed. The exploit is implemented in a single Python script ('cve_2022_39227.py') that takes a valid JWT token and allows the user to inject arbitrary claims into the payload. The script then reconstructs a new JWT token using the original signature, which may be accepted by vulnerable backends. The exploit requires the attacker to have a valid JWT and targets applications using the affected 'python-jwt' library for authentication or authorization. The repository includes standard documentation and licensing files, with the main functionality contained in the Python script. No hardcoded network endpoints or IP addresses are present; the exploit is generic and intended to be used against any vulnerable service using JWTs with the affected library.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.