Top 10 web hacking techniques of 2025

2026-07-10T20:51:55Zf0f4c615800fc938461bd1f1ee05ed41c4c0ce4bf19ba8f207b3e69b34fadb03
authentication-bypasscache-poisoningcookie-prefixescookie-securitycsp-bypasscss-exfiltrationgitlabhttp-desynchttp1.1http2httponly-bypassjwt-forgeryphp-samlportswiggerrequest-smugglingruby-samlsamlsignsaboteursingle-packet-attacktiming-attacksurl-validation-bypasswaf-bypassweb-securitywebsocketxss

What happened

This PortSwigger Research collection (2024–2026) aggregates multiple high-impact web-security findings and tooling advances. Notable technical results include parser-level SAML inconsistencies that enable full authentication bypasses (ruby-saml/php SAML ecosystems and a GitLab chain demonstrating unauthenticated admin access), new HTTP desync/request-smuggling exploitation techniques (including TRACE-based and HTTP/1.1 desync endgame analysis) that enable takeover and cache poisoning, methods for bypassing cookie prefix protections (__Host / __Secure) and the HttpOnly flag (cookie sandwich), a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
portswigger_research
Record identifier
f0f4c615800fc938461bd1f1ee05ed41c4c0ce4bf19ba8f207b3e69b34fadb03
Enrichment time
2026-07-10T20:51:55Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.