CSS:the bomb inside your inbox
2026-08-21T20:51:50Z•99c2ada9165e4ab8afe420c7b23bebb8df4eca57a80d8ae8ec5393c5491fc16a
ai-security-researchauthentication-bypasscookie-securitycorscrlf-injectioncsp-bypasscss-injectiondata-exfiltrationhttp-desynchronizationjwtoffensive-securityopen-redirectparser-discrepancyrequest-smugglingsamlssrftiming-attackstoken-forgeryunicode-overflowurl-validation-bypassweb-application-securityweb-cache-poisoningweb-securitywebsocketsxss
What happened
PortSwigger Research feed containing recent web security research on HTTP desynchronization, CSS and cookie-based data exfiltration, SAML authentication bypasses, parser discrepancies, URL validation bypasses, cache poisoning, CSP bypasses, XSS, JWT and signed-token forgery, WebSocket testing, and AI-assisted security testing. The collection is primarily offensive security research and does not identify a single product vulnerability or specific CVE.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- portswigger_research
- Record identifier
- 99c2ada9165e4ab8afe420c7b23bebb8df4eca57a80d8ae8ec5393c5491fc16a
- Enrichment time
- 2026-08-21T20:51:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.