alg: none — Python Bug Hunt
Inspired by the 2015 JWT library vulnerabilities: tokens declaring "alg": "none" were accepted without any signature at all — attackers could mint…
- Language: Python
- Layer: Backend
- Difficulty: Medium
- Concepts: Security, JWT
- Modelled on: JWT libraries · 2015
- Visible tests: a properly signed HS256 token is trusted; alg none is never trusted; a bad signature is never trusted
- Reward: 50 XP for a complete fix
Briefing
Inspired by the 2015 JWT library vulnerabilities: tokens declaring "alg": "none" were accepted without any signature at all — attackers could mint themselves any identity by just… asking nicely.
verify.py decides whether a decoded token is trustworthy.
Bug report
BUG-ALG-NONE · Priority: Critical (auth bypass) · Reported by: security
is_trusted(header, signature_ok):
- ONLY tokens with alg == "HS256" AND a valid signature are trusted
- "none", "NONE", missing alg — never trusted, signature or not
Observed: a curl with {"alg":"none"} and no signature returns admin data.
Logs
[auth] token alg=none sig=<absent> -> TRUSTED (?!)The code as shipped
src/auth/verify.py (editable)
# Decides whether a decoded JWT can be trusted.
ALLOWED_ALG = "HS256"
def is_trusted(header, signature_ok):
alg = header.get("alg")
if alg == "none":
return True
return signature_ok
Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More Python bug hunts.