Skip to content

MCP OAuth: symmetric_algorithm is not enforced (HS256 accepted with HS512 configured); schema forbids algorithms allowlist on symmetric jwks entries #3250

Description

@thebuck25

Summary

For MCP OAuth with a symmetric key, symmetric_algorithm: HS512 does not reject a token signed with HS256 using the same key. The explicit algorithms: [HS512] workaround is rejected by the configuration schema for symmetric-key entries.

Reproduced with both official images:

  • ghcr.io/wundergraph/cosmo/router:0.335.0
  • ghcr.io/wundergraph/cosmo/router:0.347.1

Reproduction

On a working router with MCP enabled and its normal execution config/operations storage, configure:

mcp:
  enabled: true
  server:
    listen_addr: '0.0.0.0:5025'
    base_url: 'https://mcp.example.com'
  oauth:
    enabled: true
    authorization_server_url: 'https://app.example.com'
    jwks:
      - secret: 'disposable-test-key-not-a-deployed-secret-123456789012345678901234567890'
        symmetric_algorithm: 'HS512'
        header_key_id: ''
        audiences: ['https://mcp.example.com/mcp']

Keep the normal MCP storage configuration. Generate two JWTs with the same disposable secret and audience, a current expiration, and no kid; sign one with HS512 and the other with HS256. For each, POST /mcp with Authorization: Bearer <token>, Content-Type: application/json, Accept: application/json, text/event-stream, and:

{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"algorithm-repro","version":"1"}}}

Observed in isolated tests of both images:

Token algorithm HTTP status
HS512 200 (successful initialize)
HS256 200 (successful initialize)

An unauthenticated request returned 401, and an unrelated audience returned 401 in the 0.335.0 test, confirming that OAuth middleware was active.

Adding algorithms: [HS512] to the symmetric entry prevents startup: configuration validation reports oneOf failed because the symmetric-key branch forbids algorithms. Omitting header_key_id also prevents startup; an empty value accepts tokens without kid.

Relevant 0.347.1 source

Expected behavior and impact

Configuring HS512 should reject HS256. This is a defense-in-depth gap for symmetric deployments: the algorithm setting suggests a restriction that is not actually enforced. The reproduction still requires a correctly signed token with the configured secret; this report does not claim authentication bypass without that key.

Please enforce symmetric_algorithm as an algorithm allowlist, or permit the explicit algorithms field on symmetric entries. A regression test covering HS512 acceptance and HS256 rejection would pin the intended behavior.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    internally-reviewedThe issue has been reviewed internally.

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions