macOS
•
xterm-256color
•
zsh
2 views
Netflix Lemur 1.9.0 — JWT verifier passes attacker-controlled alg value from token header to jwt.decode(..., algorithms=[header['alg']]). Sink: lemur/auth/service.py:130-137. Anti-pattern (CWE-347); not directly exploitable in PyJWT 2.12.1 default config (mitigates alg=none), but escalates to full ATO when chained with secret disclosure (e.g. Priam config leak). Defense-in-depth hardening. Authorized HackerOne lab.