What's in a tag name? JavaScript, apparently

2026-09-23T08:51:50Z•355536c4988be2ad963d2bb2230140865a7f0b4b20a340a4648e537b42dd1562
ai-security-researchapplication-securityauthentication-bypasscookie-securitycorscrlf-injectioncsp-bypasscss-injectiondata-exfiltrationhttp-desyncjwtoffensive-securityopen-redirectparser-discrepancyrequest-smugglingsamlssrftiming-attacksurl-validationwaf-bypassweb-cache-poisoningweb-securitywebsocketxss

What happened

PortSwigger Research feed covering web security research and offensive techniques, including HTTP desynchronization and request smuggling, authentication and SAML bypasses, cookie and WAF evasion, CSS and XSS data exfiltration, URL validation bypasses, cache poisoning, parser discrepancies, timing attacks, and AI-assisted security testing. The collection contains high-impact vulnerability research, but no single product or vulnerability is specified and no CVE identifiers are provided.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
portswigger_research
Record identifier
355536c4988be2ad963d2bb2230140865a7f0b4b20a340a4648e537b42dd1562
Enrichment time
2026-09-23T08:51:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.