signature-stripped

Signature stripping - a removed signature

A token that claims to be signed, with the signature deleted. A service treating an absent signature as nothing to check can be forged. CWE-347.

REJECT

Your service should reject this one.

Stated as the outcome to assert against, so a suite compares with this rather than hardcoding a result and getting it backwards.

The token says it is signed, but the signature has been deleted. If your app treats a missing signature as nothing to check, it can be forged by anyone.

Provenance

Kind
vulnerabilityA published weakness exists for this. Failing it is a known exploit path.
Source
built-in
Clause
RFC 7515 §5.2
CVE
none
Weakness
CWE-347

Test keys only. Nothing here is a statement about any particular service: the expected outcome above is what an application ought to do, not evidence that yours does.

Reference

URL or embedded key?

Your app needs the public key to check a token. It can fetch it from a URL at runtime, or carry it as a file. Both are normal. The trade is always the same one: who controls rotation.

Fetch from the URLEmbed the key
RotationAutomatic on next fetchNeeds a redeploy
NetworkDepends on the URLNone
TrustWhatever the endpoint servesPinned to one key
SuitsA signer that rotates keysOffline, air-gapped, or pinned

Use the URL when the signer rotates its keys, which is what every identity provider does. That is why it became the norm, and it is usually a one-line config change.

Embed the key when you cannot make a network call while checking a token, or when you want your app pinned to one key so a compromised endpoint could not introduce another. Export the PEM from the Keysets tab.

One catch worth knowing: Spring Boot's public-key-location only loads RSA keys. An ES256 or EdDSA key needs a custom decoder, or the URL.