I'm also marking this as Medium because I'm unsure of any negative impact (much less a security impact) beyond passing the same invalid token back to the client in the JSON response (... which can still be validated successfully).
I'm also marking this as Medium because I'm unsure of any negative impact (much less a security impact) beyond passing the same invalid token back to the client in the JSON response (... which can still be validated successfully).