Top 10 web hacking techniques of 2025

2026-07-14T08:51:57Z13a4f5755621c35dc8485725ca76cca3e310dc0904dc186d19e2c0f40231cae3
CSP-bypassCSS-exfiltrationHTTP-1.1HTTP-desyncHttpOnly-exfiltrationJWT-forgerySAMLSignSaboteurURL-validation-bypassWAF-bypassWebSocketXSS__Host__Secureauthentication-bypassburp-extensionscache-poisoningcookie-prefix-bypassnamespace-confusionrequest-pipeliningrequest-smugglingruby-samltiming-attackstoolingunicode-overflow

What happened

A collection of PortSwigger Research posts (Top-10 roundup plus individual disclosures) covering high-impact web‑security findings from 2024–2026. Notable items include parser-level SAML inconsistencies that enable full authentication bypasses (ruby- and PHP‑SAML chains/namespace confusion, GitLab exploitation), large-scale HTTP desync/request-smuggling problems and a call to move away from insecure HTTP/1.1 patterns, cookie‑parser discrepancies that bypass __Host/__Secure prefixes and HttpOnly protections, CSS-based exfiltration techniques, WebSocket analysis for deeper testing, JWT forging/“

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
portswigger_research
Record identifier
13a4f5755621c35dc8485725ca76cca3e310dc0904dc186d19e2c0f40231cae3
Enrichment time
2026-07-14T08:51:57Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.