What's in a tag name? JavaScript, apparently

2026-09-15T20:51:49Z•8ea45c82efa66401e86f9152e0887607200136f94c9b6d9bae6d57b58f57b7db
CRLF-injectionCSP-bypassCSS-injectionHTTP-desynchronizationJWTSAMLSSRFURL-validation-bypassVS-CodeXSSapplication-securityauthentication-bypassauthorization-bypassbrowser-securitycache-poisoningcookie-securityoffensive-securityparser-discrepancyrequest-smugglingsecurity-researchsession-hijackingtiming-attacksweb-security

What happened

PortSwigger Research feed containing web security research and offensive testing techniques published from 2024 through 2026. Topics include HTTP request smuggling and desynchronization, CSS and JavaScript injection, authentication and authorization bypasses, SAML parser inconsistencies, cookie-prefix and HttpOnly bypasses, SSRF and URL validation bypasses, cache poisoning, timing attacks, CSP bypasses, token forgery, and exploitation of parser and browser discrepancies. Several entries describe techniques capable of session theft, credential theft, administrative access, or hostile takeover,,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
portswigger_research
Record identifier
8ea45c82efa66401e86f9152e0887607200136f94c9b6d9bae6d57b58f57b7db
Enrichment time
2026-09-15T20:51:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · What's in a tag name? JavaScript, apparently · Baitaphish