CVE-2026-23993: JWT authentication bypass in HarbourJwt via “unknown alg
pentesterlab.com·1d
🧪CBOR Fuzzing
Preview
Report Post

CVE-2026-23993: JWT authentication bypass in HarbourJwt via “unknown alg”

I didn’t know Harbour even existed as a language when I found this bug. The fun part is that I also didn’t need to know Harbour to spot a critical flaw — I used an LLM as a first-pass reviewer, then validated the finding by reading the small, security-critical code paths myself.

This post covers CVE-2026-23993, an authentication bypass in HarbourJwt where any unrecognized JWT algorithm value in the header causes signature verification to be bypassed.

How I found it (without knowing Harbour)

I scanned a bunch of JWT libraries listed on jwt.io and ran an internal “jwt-library-review” skill (using Claude) on each…

Similar Posts

Loading similar posts...

Keyboard Shortcuts

Navigation
Next / previous item
j/k
Open post
oorEnter
Preview post
v
Post Actions
Love post
a
Like post
l
Dislike post
d
Undo reaction
u
Recommendations
Add interest / feed
Enter
Not interested
x
Go to
Home
gh
Interests
gi
Feeds
gf
Likes
gl
History
gy
Changelog
gc
Settings
gs
Browse
gb
Search
/
General
Show this help
?
Submit feedback
!
Close modal / unfocus
Esc

Press ? anytime to show this help