json-web-token library is vulnerable to a JWT algorithm confusion attack (CVE-2023-48238) | HOL Guard CVE