tryb

Local inspector

TRB-069v1.0.0 · jwt_remote_key_header_detected

JWT remote key header detected

JWT remote key header detected identifies security-sensitive token fields require strict validation before trust decisions.

CWE mapping

CWE-345

insufficient recognition

Assurance

The analyzer verified the reported construct is present in the supplied input.

Conditional: Impact depends on how the destination parser, runtime, or deployment is configured.

Inert example

Displayed as text only. tryb does not execute this example.

eyJhbGciOiJub25lIn0.eyJzdWIiOiIxMjMifQ.

Remediation

inspect-context. The observed property needs destination-specific policy before an automatic rewrite is safe.

Verify: Inspect the actual consumer and encode the intended acceptance rule in a test.

What to verify next

Confirm the exact production parser and security settings before treating this as exploitable.

Run the local analyzer