HTTP/3 in Burp Suite - it’s time to find a bigger wordlist

2026-09-24T08:51:47Z•8d1159bd86f8e2134ba9630141d39fc70d6d85477cc0a3463fc2696f6b9fecb6
Burp-SuiteCSP-bypassCSS-injectionHTTP-desynchronizationSAMLSSRFURL-validationWAF-bypassWebSocketsXSSauthentication-bypasscache-poisoningcookie-securitydata-exfiltrationrequest-smugglingsecurity-researchweb-application-securityweb-security

What happened

PortSwigger Research feed containing recent web security research on HTTP desynchronization, SAML authentication bypasses, cookie and WAF parsing discrepancies, CSS and CSP-based data exfiltration, URL validation bypasses, cache poisoning, XSS, WebSocket testing, and AI-assisted security testing. The collection is primarily research and tooling guidance rather than a single disclosed vulnerability; several topics describe potentially high-impact attack techniques, including authentication bypass and HTTP request smuggling/desync.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
portswigger_research
Record identifier
8d1159bd86f8e2134ba9630141d39fc70d6d85477cc0a3463fc2696f6b9fecb6
Enrichment time
2026-09-24T08:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · HTTP/3 in Burp Suite - it’s time to find a bigger wordlist · Baitaphish