CSS:the bomb inside your inbox

2026-08-20T20:51:49Zc8cd9c43a7916ba9acc58d7ac10929698cbae6a1e308341ae88b308990674dff
access-controlai-security-testingauthentication-bypassbrowser-securitycookie-securitycrlf-injectioncsp-bypasscss-injectiondata-exfiltrationhttp-desynchttponly-bypassjwtopen-redirectparser-discrepancyrequest-smugglingsamlssrftoken-forgeryurl-validationweb-application-securityweb-cache-poisoningweb-researchwebsocketsxss

What happened

PortSwigger Research feed covering web application security research from 2024–2026. Highlighted topics include CSS-based data exfiltration in webmail, CRLF and HTTP desynchronization attacks, SAML authentication bypasses, cookie-prefix and HttpOnly bypasses, URL validation flaws, web cache poisoning, parser discrepancies, CSP bypasses, signed-token forgery, and exploitation of browser or protocol inconsistencies. The collection is primarily research and tooling content rather than a single disclosed vulnerability; specific product impact and CVE assignments are not provided in the feed.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
portswigger_research
Record identifier
c8cd9c43a7916ba9acc58d7ac10929698cbae6a1e308341ae88b308990674dff
Enrichment time
2026-08-20T20:51:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CSS:the bomb inside your inbox · Baitaphish