Yes. JWT also had a bug where some implementations would use the pubkey as an hmac password if you switched the algorithm which is similarly bad.
Specifying the algorithm in the attacker controlled document is a bad design imo.
Still i feel like SAML is much worse. JWT has a few rough edges, but SAML its like everything.