
7/8 — kid / jku abuse If the output token has a different kid than the input, dig in. Issuers that resolve signing keys from kid/jku/x5u headers may fetch attacker-controlled JWKS. End state: you sign your own admin tokens. CVE-2018-0114 class bugs still ship in 2026.
Post summary
The post highlights that JWT issuers accepting kid/jku/x5u headers can fetch attacker‑controlled JWKS, allowing forged admin tokens, and notes that CVE‑2018‑0114 class bugs continue to appear in 2026.
