PortSwigger Releases Top 10 Web Hacking Techniques of 2025
PortSwigger Research has published the 19th edition of its annual Top 10 Web Hacking Techniques list for 2025. This community-driven initiative identifies the most innovative web security research from the past year through a three-step process involving community nominations, voting, and expert panel selection. The 2025 list features ten critical vulnerabilities and techniques, including parser differentials, HTTP/2 CONNECT exploitation, cross-site leaks via Chrome's connection pooling, Next.js cache poisoning, ETag length leaks, SOAP-based RCE in .NET frameworks, Unicode normalization attacks, and novel SSRF methods using HTTP redirect loops. The report highlights a decrease in nominations compared to the previous year, attributing it to the industry's focus on AI. An expert panel, including notable security researchers like Nicolas Grégoire and Soroush Dalili, finalized the rankings. The publication aims to guide security professionals and researchers toward emerging threats and effective mitigation strategies, with plans for an in-person award ceremony at DEF CON.
Wire timeline
PortSwigger Releases Top 10 Web Hacking Techniques of 2025
PortSwigger Research has published the 19th edition of its annual Top 10 Web Hacking Techniques list for 2025. This community-driven initiative identifies the most innovative web security research from the past year through a three-step process involving community nominations, voting, and expert panel selection. The 2025 list features ten critical vulnerabilities and techniques, including parser differentials, HTTP/2 CONNECT exploitation, cross-site leaks via Chrome's connection pooling, Next.js cache poisoning, ETag length leaks, SOAP-based RCE in .NET frameworks, Unicode normalization attacks, and novel SSRF methods using HTTP redirect loops. The report highlights a decrease in nominations compared to the previous year, attributing it to the industry's focus on AI. An expert panel, including notable security researchers like Nicolas Grégoire and Soroush Dalili, finalized the rankings. The publication aims to guide security professionals and researchers toward emerging threats and effective mitigation strategies, with plans for an in-person award ceremony at DEF CON.
PortSwigger Research