HTTP/3 in Burp Suite - it’s time to find a bigger wordlist

2026-09-23T20:51:48Z•905e004b1d01643190b71525f33dae2c99dd74ebb9eaf54f20936f6fc0667dc3
ai-assisted-securityauthentication-bypassauthorization-bypassburp-suitecookie-securitycsp-bypasscsrfcss-injectiondata-exfiltrationhttp-desynchronizationhttp3httponlyjwtopen-redirectparser-discrepancyrequest-smugglingsamlsecurity-testingssrftiming-attacksurl-validationweb-application-securityweb-cache-poisoningweb-security-researchxss

What happened

PortSwigger Research feed containing recent web-security research on HTTP desynchronization, SAML authentication bypasses, cookie and parser discrepancies, CSS/XSS data exfiltration, URL validation bypasses, cache attacks, CSP bypasses, timing attacks, and security-testing automation. Several articles describe potentially high-impact exploitation techniques, including authentication or authorization bypass and request-smuggling/desync attacks. No specific CVE identifiers are provided in the supplied feed metadata.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
portswigger_research
Record identifier
905e004b1d01643190b71525f33dae2c99dd74ebb9eaf54f20936f6fc0667dc3
Enrichment time
2026-09-23T20:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.