Top 10 web hacking techniques of 2025
2026-07-14T08:51:57Z•13a4f5755621c35dc8485725ca76cca3e310dc0904dc186d19e2c0f40231cae3
CSP-bypassCSS-exfiltrationHTTP-1.1HTTP-desyncHttpOnly-exfiltrationJWT-forgerySAMLSignSaboteurURL-validation-bypassWAF-bypassWebSocketXSS__Host__Secureauthentication-bypassburp-extensionscache-poisoningcookie-prefix-bypassnamespace-confusionrequest-pipeliningrequest-smugglingruby-samltiming-attackstoolingunicode-overflow
What happened
A collection of PortSwigger Research posts (Top-10 roundup plus individual disclosures) covering high-impact web‑security findings from 2024–2026. Notable items include parser-level SAML inconsistencies that enable full authentication bypasses (ruby- and PHP‑SAML chains/namespace confusion, GitLab exploitation), large-scale HTTP desync/request-smuggling problems and a call to move away from insecure HTTP/1.1 patterns, cookie‑parser discrepancies that bypass __Host/__Secure prefixes and HttpOnly protections, CSS-based exfiltration techniques, WebSocket analysis for deeper testing, JWT forging/“
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- portswigger_research
- Record identifier
- 13a4f5755621c35dc8485725ca76cca3e310dc0904dc186d19e2c0f40231cae3
- Enrichment time
- 2026-07-14T08:51:57Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.