CSS:the bomb inside your inbox

2026-08-21T20:51:50Z99c2ada9165e4ab8afe420c7b23bebb8df4eca57a80d8ae8ec5393c5491fc16a
ai-security-researchauthentication-bypasscookie-securitycorscrlf-injectioncsp-bypasscss-injectiondata-exfiltrationhttp-desynchronizationjwtoffensive-securityopen-redirectparser-discrepancyrequest-smugglingsamlssrftiming-attackstoken-forgeryunicode-overflowurl-validation-bypassweb-application-securityweb-cache-poisoningweb-securitywebsocketsxss

What happened

PortSwigger Research feed containing recent web security research on HTTP desynchronization, CSS and cookie-based data exfiltration, SAML authentication bypasses, parser discrepancies, URL validation bypasses, cache poisoning, CSP bypasses, XSS, JWT and signed-token forgery, WebSocket testing, and AI-assisted security testing. The collection is primarily offensive security research and does not identify a single product vulnerability or specific CVE.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
portswigger_research
Record identifier
99c2ada9165e4ab8afe420c7b23bebb8df4eca57a80d8ae8ec5393c5491fc16a
Enrichment time
2026-08-21T20:51:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.