What's in a tag name? JavaScript, apparently

2026-09-18T08:51:48Z•0ea006f43dd898d42614626a83e10d0a9d8f142b491ae09b2e80577b5f8b1c48
AI-security-testingCSP-bypassCSS-injectionHTTP-desynchronizationSAMLSSRFURL-validationWAF-bypassWebSocketXSSauthentication-bypasscookie-securitydata-exfiltrationopen-redirectparser-discrepancyrequest-smugglingtiming-attacksweb-application-securityweb-cache-poisoningweb-research

What happened

PortSwigger Research feed covering web application security research from 2024–2026, including HTTP desynchronization and request smuggling, parser discrepancies, SAML authentication bypasses, cookie and WAF bypasses, CSS and XSS data exfiltration, URL validation weaknesses, cache poisoning, timing attacks, CSP bypasses, and AI-assisted security testing. Several entries describe high-impact attack techniques that can enable authentication bypass, credential or cookie theft, SSRF, request hijacking, or web cache compromise. No specific product version or confirmed CVE identifiers are provided.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
portswigger_research
Record identifier
0ea006f43dd898d42614626a83e10d0a9d8f142b491ae09b2e80577b5f8b1c48
Enrichment time
2026-09-18T08:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.