Uppsats

Security Vulnerabilities in AI-Generated JWT Authentication Code for Spring Boot

Kandidat-uppsats

Linnéuniversitetet/Institutionen för datavetenskap och medieteknik (DM)

Publicerad: 2026

Språk: Engelska

Sammanfattning

The rapid adoption of AI-assisted programming tools has introduced new challenges forsoftware security, particularly when developers use large language models to generatesecurity-critical code. This study investigates the security vulnerabilities present in AI-generated JWT authentication code for Java Spring Boot Representational State TransferApplication Programming Interfaces (REST API), a domain that existing literature has notspecifically examined. Using a controlled experimental design, 60 code variants weregenerated by two AI models, Gemma 4 and Qwen 3 Coder Plus, and analysed using twocomplementary Static Application Security Testing (SAST) tools, SonarQube andSpotBugs. Every generated variant contained at least one security-relevant finding acrosseight distinct Common Weakness Enumeration (CWE) categories. The two modelsproduced meaningfully different vulnerability profiles, with neither clearly outperformingthe other from a security standpoint. The findings reinforce that AI-generated JSON WebToken (JWT) authentication code requires dedicated security review.

Information

Lärosäte / institution
Linnéuniversitetet/Institutionen för datavetenskap och medieteknik (DM)
Publiceringsdatum
2026
Uppsatstyp
Kandidat-uppsats
Språk
Engelska

Utforska vidare

Liknande uppsatser

Uppsatser med liknande ämnen och nyckelord.

Casemanagement

M1-uppsats, Mittuniversitetet/Institutionen för data- och elektroteknik (2023-)

Persdotter, Amanda

Publicerad: 2026

Spring Boot