What's in a tag name? JavaScript, apparently

2026-09-16T08:51:48Z•cee302b1c6b2969190a4b79c8f44bb3ef8eadacb646c0e87932e13d369fb056b
CRLF-injectionCSP-bypassCSS-injectionHTTP-desynchronizationJWTJavaScriptSAMLSSRFURL-validationWAF-bypassWebSocketXSSaccess-controlapplication-securityauthentication-bypasscookie-securityopen-redirectrequest-smugglingsecurity-researchtiming-attackstoken-forgeryweb-cache-poisoningweb-security

What happened

PortSwigger Research feed containing recent web security research on HTTP desynchronization, CSS and JavaScript injection, authentication and SAML parser bypasses, cookie and WAF bypasses, SSRF and URL validation, cache poisoning, XSS, CSP bypasses, token forgery, timing attacks, and related offensive testing techniques. The document is an aggregation of research articles rather than a single product vulnerability disclosure; no specific CVE identifiers are provided.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
portswigger_research
Record identifier
cee302b1c6b2969190a4b79c8f44bb3ef8eadacb646c0e87932e13d369fb056b
Enrichment time
2026-09-16T08:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.