What's in a tag name? JavaScript, apparently

2026-09-01T20:51:48Z7a009f345e09721a49664b8054c2ec7bb769eaa6fa57fc764cb7f7a8fc02ff91
access-controlauthentication-bypasscookie-securitycsp-bypasscss-injectiondata-exfiltrationhttp-desynchronizationoffensive-securityparser-discrepancyrequest-smugglingsamlsecurity-researchsession-hijackingssrftiming-attacksurl-validationweb-application-securityweb-cache-poisoningweb-securityxss

What happened

PortSwigger Research feed containing web security research and offensive testing techniques, including HTTP desynchronization, SAML authentication bypasses, CSS and cookie attacks, URL validation bypasses, cache exploitation, XSS, CSP bypasses, parser discrepancies, and AI-assisted security testing. Several entries describe potentially high-impact authentication bypass, session theft, request smuggling, and data exfiltration techniques, but the document is an aggregated research index rather than a report of a specific exploitable product vulnerability.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
portswigger_research
Record identifier
7a009f345e09721a49664b8054c2ec7bb769eaa6fa57fc764cb7f7a8fc02ff91
Enrichment time
2026-09-01T20:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.