security.nuyts.tech
CVE-2020-26160 – NuytsTech Security
jwt-go before 4.0.0-preview1 allows attackers to bypass intended access restrictions in situations with []string{} for m["aud"] (which is allowed by t