JWT authentication bypass via unverified signature – PortSwigger Write Up
Walkthrough of the PortSwigger lab on JWT authentication bypass through unverified signatures, explaining how to exploit this vulnerability when the server doesn't properly validate token signatures.