Top 10 web hacking techniques of 2025
2026-07-10T20:51:55Z•f0f4c615800fc938461bd1f1ee05ed41c4c0ce4bf19ba8f207b3e69b34fadb03
authentication-bypasscache-poisoningcookie-prefixescookie-securitycsp-bypasscss-exfiltrationgitlabhttp-desynchttp1.1http2httponly-bypassjwt-forgeryphp-samlportswiggerrequest-smugglingruby-samlsamlsignsaboteursingle-packet-attacktiming-attacksurl-validation-bypasswaf-bypassweb-securitywebsocketxss
What happened
This PortSwigger Research collection (2024–2026) aggregates multiple high-impact web-security findings and tooling advances. Notable technical results include parser-level SAML inconsistencies that enable full authentication bypasses (ruby-saml/php SAML ecosystems and a GitLab chain demonstrating unauthenticated admin access), new HTTP desync/request-smuggling exploitation techniques (including TRACE-based and HTTP/1.1 desync endgame analysis) that enable takeover and cache poisoning, methods for bypassing cookie prefix protections (__Host / __Secure) and the HttpOnly flag (cookie sandwich), a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- portswigger_research
- Record identifier
- f0f4c615800fc938461bd1f1ee05ed41c4c0ce4bf19ba8f207b3e69b34fadb03
- Enrichment time
- 2026-07-10T20:51:55Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.