Top 10 web hacking techniques of 2025
2026-04-22T08:52:02Z•e95fdf8d2b805f7961c2861b8920c3b43bab40b36b8ff4a3a247279f4930dea3
CSP-bypassCSS-exfiltrationHTTP-desyncHttpOnly-bypassJWT-forgerySAMLSSRFURL-validation-bypassWAF-bypassWebSocketauthentication-bypasscache-poisoningcookie-prefix-bypassportswiggerrequest-smugglingresearchweb
What happened
Collection of PortSwigger Research posts (2024–2026) that survey and introduce numerous practical and novel web attack techniques. Highlights include parser-level SAML authentication bypasses (full auth/unauthenticated admin on some ruby-saml/PHP stacks), HTTP/1.1 desynchronisation and request-smuggling exploitation (including TRACE-assisted desyncs), cookie-prefix and HttpOnly bypass techniques (session hijacking), JWT signing/forgery tooling (SignSaboteur), CSS-based exfiltration, WebSocket fuzzing/exploitation tooling, URL validation/SSRF payloads, cache poisoning variants, WAF bypasses, X‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- portswigger_research
- Record identifier
- e95fdf8d2b805f7961c2861b8920c3b43bab40b36b8ff4a3a247279f4930dea3
- Enrichment time
- 2026-04-22T08:52:02Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.