Top 10 web hacking techniques of 2025

2026-04-22T08:52:02Ze95fdf8d2b805f7961c2861b8920c3b43bab40b36b8ff4a3a247279f4930dea3
CSP-bypassCSS-exfiltrationHTTP-desyncHttpOnly-bypassJWT-forgerySAMLSSRFURL-validation-bypassWAF-bypassWebSocketauthentication-bypasscache-poisoningcookie-prefix-bypassportswiggerrequest-smugglingresearchweb

What happened

Collection of PortSwigger Research posts (2024–2026) that survey and introduce numerous practical and novel web attack techniques. Highlights include parser-level SAML authentication bypasses (full auth/unauthenticated admin on some ruby-saml/PHP stacks), HTTP/1.1 desynchronisation and request-smuggling exploitation (including TRACE-assisted desyncs), cookie-prefix and HttpOnly bypass techniques (session hijacking), JWT signing/forgery tooling (SignSaboteur), CSS-based exfiltration, WebSocket fuzzing/exploitation tooling, URL validation/SSRF payloads, cache poisoning variants, WAF bypasses, X‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
portswigger_research
Record identifier
e95fdf8d2b805f7961c2861b8920c3b43bab40b36b8ff4a3a247279f4930dea3
Enrichment time
2026-04-22T08:52:02Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.