There is in fact a long lineage of vulnerabilities caused by JWTs in real applications.

[dead]