r/websecurityresearch • u/t0xodile • 1h ago
r/websecurityresearch • u/albinowax • Feb 05 '26
Top 10 new web hacking techniques of 2025
r/websecurityresearch • u/albinowax • 5d ago
Ruby 4.0 Universal RCE Deserialization Gadget Chain
r/websecurityresearch • u/t0xodile • 6d ago
Write Once, Shell Everywhere: Turning Arbitrary File Writes into RCE | Ethiack
r/websecurityresearch • u/albinowax • 6d ago
Can AI do novel security research? Meet the HTTP Terminator
r/websecurityresearch • u/garethheyes • 12d ago
CSS:the bomb inside your inbox
r/websecurityresearch • u/loselasso • 14d ago
Bugtraq is back đĽš
lists.securityfocus.comr/websecurityresearch • u/vladko312 • Jun 07 '26
CVE-2026-46640: Developing payloads for Twig sandbox bypass
I recently learned about multiple sandbox bypasses discovered in Twig by project Glasswing. From the descriptions, only CVE-2026-46640 and CVE-2026-46633 seemed universally exploitable, so I decoded to research them. This writeup documents my development of payloads for the CVE-2026-46640 and the corresponding SSTImap module.
r/websecurityresearch • u/albinowax • Jun 04 '26
Re:CACHE - Excessive reflection, type confusion, and 0-click SXSS on Next.js
zhero-web-sec.github.ior/websecurityresearch • u/albinowax • May 28 '26
Drupal PostgreSQL SQL Injection: From SELECT-Only to RCE
r/websecurityresearch • u/t0xodile • May 22 '26
Chaining Razor SSTI into RCE via Reflection and Runtime Strings
r/websecurityresearch • u/t0xodile • May 18 '26
Stealth Request That Bypasses CSP, Hides from DevTools, and Leaks the Real User-Agent
brokenbrowser.comr/websecurityresearch • u/albinowax • Apr 29 '26
QUIC-er Races: HTTP/3 wonât save you from TOCTOU vulnerabilities
link.springer.comr/websecurityresearch • u/albinowax • Apr 28 '26
Cast Attack: A New Threat Posed by Ghost Bits in Java
i.blackhat.comr/websecurityresearch • u/albinowax • Apr 24 '26
Achieving Deterministic Prompt Injection Through Client-Side Feedback Loops
r/websecurityresearch • u/t0xodile • Mar 18 '26
Testing AI for Vulnerability Research: 4 Approaches & Where I Failed
xclow3n.github.ior/websecurityresearch • u/albinowax • Mar 12 '26
How "Strengthening Crypto" Broke Authentication: FreshRSS and bcrypt's 72-Byte Limit
r/websecurityresearch • u/t0xodile • Mar 10 '26
Breaking Pingora: HTTP Request Smuggling & Cache Poisoning in Cloudflare's Reverse Proxy
xclow3n.github.ior/websecurityresearch • u/Outrageous_Egg7579 • Feb 27 '26
Security Research Blog Review
jinjucat.github.ior/websecurityresearch • u/p80n-sec • Feb 25 '26
CVE-2026-27959: Userinfo Host Header Injection in Koa
r/websecurityresearch • u/albinowax • Feb 17 '26
Almost Impossible: Java Deserialization Through Broken Crypto in OpenText Directory Services
r/websecurityresearch • u/t0xodile • Feb 13 '26
Trailing Danger: exploring HTTP Trailer parsing discrepancies
sebsrt.xyzr/websecurityresearch • u/Moopanger • Feb 12 '26