> ## Documentation Index
> Fetch the complete documentation index at: https://docs.codeant.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Jjwt none alg

<AccordionGroup>
  <Accordion title="jjwt-none-alg">
    Detected use of the `none` algorithm in a JWT token. The `none` algorithm assumes the integrity of the token has already been verified. This would allow a malicious actor to forge a JWT token that will automatically be verified. Do not explicitly use the `none` algorithm. Instead, use an algorithm such as `HS256`.<br />**Likelihood**: LOW<br />**Confidence**: LOW<br />**CWE**: <br />- CWE-327: Use of a Broken or Risky Cryptographic Algorithm
    <br />**OWASP**: <br />- A02:2021 - Cryptographic Failures
    <br />- A03:2017 - Sensitive Data Exposure
  </Accordion>
</AccordionGroup>
