What's in a tag name? JavaScript, apparently
2026-09-23T08:51:50Z•355536c4988be2ad963d2bb2230140865a7f0b4b20a340a4648e537b42dd1562
ai-security-researchapplication-securityauthentication-bypasscookie-securitycorscrlf-injectioncsp-bypasscss-injectiondata-exfiltrationhttp-desyncjwtoffensive-securityopen-redirectparser-discrepancyrequest-smugglingsamlssrftiming-attacksurl-validationwaf-bypassweb-cache-poisoningweb-securitywebsocketxss
What happened
PortSwigger Research feed covering web security research and offensive techniques, including HTTP desynchronization and request smuggling, authentication and SAML bypasses, cookie and WAF evasion, CSS and XSS data exfiltration, URL validation bypasses, cache poisoning, parser discrepancies, timing attacks, and AI-assisted security testing. The collection contains high-impact vulnerability research, but no single product or vulnerability is specified and no CVE identifiers are provided.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- portswigger_research
- Record identifier
- 355536c4988be2ad963d2bb2230140865a7f0b4b20a340a4648e537b42dd1562
- Enrichment time
- 2026-09-23T08:51:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.