From the specificaiton: Even if a JWT can be successfully validated, unless the algorithm(s) used in the JWT are acceptable to the application, it SHOULD reject the JWT.
So what it is saying is that you should have code in your application to make sure to only trust algorithms that you like.
The other issue is that following the specifications rules for validation get you in a hairy spot where this vulnerability exist:
https://tools.ietf.org/html/draft-ietf-oauth-json-web-token-...