13/02/2026
If a JWT token uses "alg": "none" and the server accepts it without verifying the signature, what is the issue?
A) Information Disclosure
B) Broken Authentication
C) Cryptographic Misconfiguration
D) CSRF
๐ Whatโs your answer?