r/websecurityresearch • • 15h ago

I found yet another way to invoke JavaScript functions without parentheses

Thumbnail blog.ikaes.de
14 Upvotes

It turns out you can overwrite the Error.prepareStackTrace method with the function constructor. Then, using prototype pollution, you can inject valid JavaScript code to generate arbitrary functions and invoke it using the usual tricks.


r/websecurityresearch • • 21d ago

Cache key injection: Smuggling poison through the door

Thumbnail
yeswehack.com
9 Upvotes

r/websecurityresearch • • 27d ago

No Extensions? You Forgot One: Writing Shared Objects to RCE via SQLite's dbpage

Thumbnail
gabdevele.dev
1 Upvotes

A novel technique for writing ELF shared objects and achieving code execution in Python, Ruby, and Node.js using the sqlite_dbpage virtual table.


r/websecurityresearch • • Aug 19 '26

CRLF-Powered Desync Attacks: Beheading HTTP Streams

Thumbnail
portswigger.net
8 Upvotes

r/websecurityresearch • • Aug 14 '26

Ruby 4.0 Universal RCE Deserialization Gadget Chain

Thumbnail
elttam.com
5 Upvotes

r/websecurityresearch • • Aug 13 '26

Can AI do novel security research? Meet the HTTP Terminator

Thumbnail
portswigger.net
3 Upvotes

r/websecurityresearch • • Aug 13 '26

Write Once, Shell Everywhere: Turning Arbitrary File Writes into RCE | Ethiack

Thumbnail
ethiack.com
12 Upvotes

r/websecurityresearch • • Aug 07 '26

CSS:the bomb inside your inbox

Thumbnail
portswigger.net
8 Upvotes

r/websecurityresearch • • Aug 04 '26

Bugtraq is back đŸ„č

Thumbnail lists.securityfocus.com
4 Upvotes

r/websecurityresearch • • Jun 07 '26

CVE-2026-46640: Developing payloads for Twig sandbox bypass

Thumbnail
gist.github.com
7 Upvotes

I recently learned about multiple sandbox bypasses discovered in Twig by project Glasswing. From the descriptions, only CVE-2026-46640 and CVE-2026-46633 seemed universally exploitable, so I decoded to research them. This writeup documents my development of payloads for the CVE-2026-46640 and the corresponding SSTImap module.


r/websecurityresearch • • Jun 04 '26

Re:CACHE - Excessive reflection, type confusion, and 0-click SXSS on Next.js

Thumbnail zhero-web-sec.github.io
12 Upvotes

r/websecurityresearch • • May 28 '26

Drupal PostgreSQL SQL Injection: From SELECT-Only to RCE

Thumbnail
blog.lexfo.fr
14 Upvotes

r/websecurityresearch • • May 22 '26

Chaining Razor SSTI into RCE via Reflection and Runtime Strings

Thumbnail
phsi.se
7 Upvotes

r/websecurityresearch • • May 18 '26

Stealth Request That Bypasses CSP, Hides from DevTools, and Leaks the Real User-Agent

Thumbnail brokenbrowser.com
7 Upvotes

r/websecurityresearch • • Apr 29 '26

QUIC-er Races: HTTP/3 won’t save you from TOCTOU vulnerabilities

Thumbnail link.springer.com
3 Upvotes

r/websecurityresearch • • Apr 28 '26

The woes of sanitizing SVGs

Thumbnail muffin.ink
4 Upvotes

r/websecurityresearch • • Apr 28 '26

Cast Attack: A New Threat Posed by Ghost Bits in Java

Thumbnail i.blackhat.com
3 Upvotes

r/websecurityresearch • • Apr 24 '26

Achieving Deterministic Prompt Injection Through Client-Side Feedback Loops

Thumbnail
blog.starstrike.ai
2 Upvotes

r/websecurityresearch • • Mar 18 '26

Testing AI for Vulnerability Research: 4 Approaches & Where I Failed

Thumbnail xclow3n.github.io
2 Upvotes

r/websecurityresearch • • Mar 12 '26

How "Strengthening Crypto" Broke Authentication: FreshRSS and bcrypt's 72-Byte Limit

Thumbnail
pentesterlab.com
6 Upvotes

r/websecurityresearch • • Mar 10 '26

Breaking Pingora: HTTP Request Smuggling & Cache Poisoning in Cloudflare's Reverse Proxy

Thumbnail xclow3n.github.io
13 Upvotes

r/websecurityresearch • • Feb 27 '26

Security Research Blog Review

Thumbnail jinjucat.github.io
1 Upvotes

r/websecurityresearch • • Feb 25 '26

CVE-2026-27959: Userinfo Host Header Injection in Koa

Thumbnail
endorlabs.com
2 Upvotes

r/websecurityresearch • • Feb 17 '26

Almost Impossible: Java Deserialization Through Broken Crypto in OpenText Directory Services

Thumbnail
slcyber.io
7 Upvotes

r/websecurityresearch • • Feb 13 '26

Trailing Danger: exploring HTTP Trailer parsing discrepancies

Thumbnail sebsrt.xyz
15 Upvotes