HTTP/3 in Burp Suite - it’s time to find a bigger wordlist
2026-09-23T20:51:48Z•905e004b1d01643190b71525f33dae2c99dd74ebb9eaf54f20936f6fc0667dc3
ai-assisted-securityauthentication-bypassauthorization-bypassburp-suitecookie-securitycsp-bypasscsrfcss-injectiondata-exfiltrationhttp-desynchronizationhttp3httponlyjwtopen-redirectparser-discrepancyrequest-smugglingsamlsecurity-testingssrftiming-attacksurl-validationweb-application-securityweb-cache-poisoningweb-security-researchxss
What happened
PortSwigger Research feed containing recent web-security research on HTTP desynchronization, SAML authentication bypasses, cookie and parser discrepancies, CSS/XSS data exfiltration, URL validation bypasses, cache attacks, CSP bypasses, timing attacks, and security-testing automation. Several articles describe potentially high-impact exploitation techniques, including authentication or authorization bypass and request-smuggling/desync attacks. No specific CVE identifiers are provided in the supplied feed metadata.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- portswigger_research
- Record identifier
- 905e004b1d01643190b71525f33dae2c99dd74ebb9eaf54f20936f6fc0667dc3
- Enrichment time
- 2026-09-23T20:51:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.