Top 10 web hacking techniques of 2025

2026-07-21T20:51:53Zfd65fb970fbfe6e00a8b91c44178a4b8ad258dbfcfa90ef8f660480d25f360b4
SAMLauthentication-bypasscookie-prefix-bypasscookiescss-exfiltrationhttp-desynchttponly-bypassjwt-forgeryparser-inconsistencyrequest-smugglingresearch-collectiontoolingwebwebsocket

What happened

This PortSwigger Research collection (Top 10 Web Hacking Techniques of 2025 and related posts) surveys a year of high-impact web security research. Key findings include parser-level SAML inconsistencies that enable full authentication bypasses in Ruby and PHP SAML ecosystems (leading to unauthenticated admin access on targets such as GitLab Enterprise), widespread HTTP desynchronisation (desync) and request-smuggling techniques that can enable host takeover, new techniques to bypass cookie protections (__Host / __Secure prefixes and HttpOnly), novel CSS/inline-style exfiltration primitives, a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
portswigger_research
Record identifier
fd65fb970fbfe6e00a8b91c44178a4b8ad258dbfcfa90ef8f660480d25f360b4
Enrichment time
2026-07-21T20:51:53Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.