What's in a tag name? JavaScript, apparently
2026-09-15T20:51:49Z•8ea45c82efa66401e86f9152e0887607200136f94c9b6d9bae6d57b58f57b7db
CRLF-injectionCSP-bypassCSS-injectionHTTP-desynchronizationJWTSAMLSSRFURL-validation-bypassVS-CodeXSSapplication-securityauthentication-bypassauthorization-bypassbrowser-securitycache-poisoningcookie-securityoffensive-securityparser-discrepancyrequest-smugglingsecurity-researchsession-hijackingtiming-attacksweb-security
What happened
PortSwigger Research feed containing web security research and offensive testing techniques published from 2024 through 2026. Topics include HTTP request smuggling and desynchronization, CSS and JavaScript injection, authentication and authorization bypasses, SAML parser inconsistencies, cookie-prefix and HttpOnly bypasses, SSRF and URL validation bypasses, cache poisoning, timing attacks, CSP bypasses, token forgery, and exploitation of parser and browser discrepancies. Several entries describe techniques capable of session theft, credential theft, administrative access, or hostile takeover,,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- portswigger_research
- Record identifier
- 8ea45c82efa66401e86f9152e0887607200136f94c9b6d9bae6d57b58f57b7db
- Enrichment time
- 2026-09-15T20:51:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.