CSS:the bomb inside your inbox
2026-08-12T20:51:49Z•780ef119de41236968bf6ba97b2fd9eeefadf23a1b38727f36ec0270d8d375f0
access-controlauthentication-bypasscache-poisoningcookie-securitycrlf-injectioncsp-bypasscss-injectiondata-exfiltrationhttp-desynchronizationhttp-request-smugglingjwtoffensive-securityopen-redirectparser-discrepancyresearchsamlsession-hijackingssrftoken-forgeryunicode-obfuscationurl-parser-confusionweb-application-securityweb-securitywebsocket-securityxss
What happened
PortSwigger Research feed covering web security research and offensive testing techniques, including CSS and style injection data exfiltration, HTTP request smuggling and desynchronization, SAML authentication bypasses, cookie and URL parser discrepancies, cache poisoning, CSP bypasses, JWT/token forgery, Unicode and control-character payload obfuscation, and AI-assisted security testing. Several entries describe potentially critical attack classes such as authentication bypass, session-cookie theft, HTTP stream desynchronization, SSRF, and administrative access compromise. The feed is a broad
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- portswigger_research
- Record identifier
- 780ef119de41236968bf6ba97b2fd9eeefadf23a1b38727f36ec0270d8d375f0
- Enrichment time
- 2026-08-12T20:51:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.