Top 10 web hacking techniques of 2025

2026-04-02T20:51:55Zb5d5f0abf2cfd701f89c9e51a7ce3493063c16fac407b4da68075b2ab8175b80
AI-assisted testingBurp Suite extensionsCSS exfiltrationHTTP desyncHTTP/1.1HttpOnly bypassIDORJWT forgerySAMLSSRFURL validation bypassUnicode overflowWAF bypassWebSocket securityXSSauthentication bypasscache poisoningcookie prefix bypasscookie sandwichnamespace confusionparser inconsistenciesrequest smugglingtiming attacksvscode exploitweb security

What happened

Collection of PortSwigger Research publications (2024–2026) covering a broad set of novel web‑security techniques and practical exploit concepts. Notable findings include parser‑level SAML authentication bypasses (attribute pollution and namespace confusion) enabling unauthenticated admin access in some ruby/php SAML deployments; deep analysis and new exploitation methods for HTTP desync/request‑smuggling and HTTP/1.1 weaknesses that can lead to takeover scenarios; cookie prefix and HttpOnly bypasses (cookie sandwich / phantom $Version cookie); CSS‑based data exfiltration techniques; JWT/sign‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
portswigger_research
Record identifier
b5d5f0abf2cfd701f89c9e51a7ce3493063c16fac407b4da68075b2ab8175b80
Enrichment time
2026-04-02T20:51:55Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.