• Blackhat Pakistan — Ethical Hacking, Hacking Tools & Cybersecurity Tutorials

OWASP Top 10 2026: 2025 List Changes and Test Steps

Blackhatpakistan

Administrator
Staff member
Joined
Dec 30, 2024
Messages
399
Reaction score
209
Points
62
Website
blackhatpakistan.net
Points
1,198
USD
1,198
The OWASP Top 10 is the Open Web Application Security Project's ranked list of the ten most critical web application risks, and the current version is OWASP Top 10:2025 — released at Global AppSec Washington in November 2025 with the final edition published January 2026, featuring two brand-new categories, eight re-ranked or renamed entries, and SSRF folded into Broken Access Control.

TL;DR - The 2025 list keeps Broken Access Control at #1 for the fourth cycle straight, promotes Security Misconfiguration to #2, introduces Software Supply Chain Failures (#3) and Mishandling of Exceptional Conditions (#10), and maps 248 CWEs total. 3.73% of applications tested had a broken access control flaw — the highest hit rate on the board. Each risk below ships with a test step you can run today: IDOR probes, misconfig scans, dependency audits, injection payloads. The OWASP Top 10 is a checklist, not a certification — run it against your own app before someone else does.

fzbesh.png


WHAT CHANGED IN THE OWASP TOP 10:2025

The 2025 edition is the first update since 2021, built from four years of submitted test data and community survey votes. The structural moves:

- A03 Software Supply Chain Failures - NEW. Expands the old Vulnerable and Outdated Components into the full dependency ecosystem: build systems, package managers, distribution channels. Fewest data occurrences, highest average CVE exploit scores.

- A10 Mishandling of Exceptional Conditions - NEW. 24 CWEs covering error handling, failing open, NULL derefs, missing parameters. Error messages that leak, and code paths that degrade insecurely instead of safely.

- SSRF absorbed into A01. Server-side request forgery is no longer its own line — OWASP now classifies it as a specific manifestation of broken access control.

- Security Misconfiguration climbed #5 to #2. Configuration-driven behavior keeps growing, and the data followed.

- Three renames that matter for tool mappings: Authentication Failures (dropped "Identification"), Software or Data Integrity Failures, and Security Logging and Alerting Failures (dropped "Monitoring" — great logging nobody alerts on is worth nothing).

- 248 mapped CWEs across the list, up from 218 in 2021. A01 alone carries 40.

A01:2025 - BROKEN ACCESS CONTROL (TEST IT FIRST)

Forty CWEs under one roof: IDOR, path traversal, missing function-level checks, CORS misconfiguration, force browsing to privileged pages, SSRF. This is where the exploitable money sits because access control bugs need no exotic payload — just a changed parameter.

Code:
# IDOR sweep - swap identifiers, watch for 200s you should not get

for uid in 1001 1002 1003; do

  curl -s -o /dev/null -w "%{http_code} " -H "Cookie: session=VALID" \

    "https://app.target.com/api/users/$uid"

done

# Force browsing - authenticated page accessed with no session

curl -s -o /dev/null -w "%{http_code}\n" "https://app.target.com/admin/dashboard"

# Path traversal on file endpoints

# SSRF probe (now tested under A01)

curl -s "https://app.target.com/fetch?url=http://169.254.169[.]254/latest/meta-data/"

Fix shape: deny by default, deny at the object level with ownership checks, never leak existence — return 404 for objects the caller cannot see, not 403.

A02:2025 - SECURITY MISCONFIGURATION

Default accounts still shipping, stack traces in production, directory listing on, CORS set to wildcard with credentials, cloud storage buckets open, debug endpoints exposed. The test is enumeration before exploitation:

Code:
# Full sweep: probe common misconfig paths, then read the banners

ffuf -u "https://target.tld/FUZZ" -w /usr/share/seclists/Discovery/Web-Content/common.txt \

  -mc 200,301,403,500 -t 60 -o misconfig.json -of json

# Header hygiene: missing security headers

curl -sI https://target.tld | grep -iE "strict-transport|x-content-type|content-security|x-frame"

# Verbose errors - send malformed input, read the response

curl -s -X POST https://target.tld/login -d "user=%INVALID%&pass=1" | head -30

Configuration belongs in version control and pipelines — one hardened baseline, applied identically across dev, staging and production, with automated drift checks.

yhbd5o.png


A03:2025 - SOFTWARE SUPPLY CHAIN FAILURES

The dependency you pulled six months ago got compromised; your lockfile now installs a loader at build time. This category covers vulnerable packages, typosquatting, malicious post-install scripts, tampered CI artifacts, and unsigned updates. Test it in one command per ecosystem:

Code:
# Node - audit + check for install scripts you did not approve

npm audit --omit=dev

npm ls --all 2>/dev/null | grep -E "\+--" | head -40

# Python - known-vulnerable deps + dependency confusion surfaces

pip-audit -r requirements.txt

pip install --dry-run internal-package-name 2>&1 | grep -i "not found"

# Lockfile integrity - anything that writes during install is your attack surface

grep -A3 '"postinstall"' package.json

Pin versions, verify lockfile hashes in CI, and treat every post-install script as remote code execution you have chosen to run.

A04:2025 - CRYPTOGRAPHIC FAILURES

Data at rest without encryption, weak cipher suites still negotiated, MD5/SHA1 for passwords, hardcoded keys in client bundles, HTTP where HTTPS should be, sensitive data in URLs that land in logs. Test the surface:

Code:
# TLS grade and protocol support

nmap --script ssl-enum-ciphers -p 443 target.tld

# Password storage format leaks (bcrypt/argon2 good, MD5/sha1 bad)

grep -rniE "md5|sha1" /var/log/app/debug.log

# Check for sensitive data in transit - look for plaintext form posts

curl -s http://target.tld/login | grep -i "type=.password" | grep -vi action

Default: encrypt everything sensitive with modern ciphers (AES-GCM, ChaCha20), argon2id or bcrypt for passwords, TLS 1.2 minimum with 1.3 preferred.

A05:2025 - INJECTION

SQL, NoSQL, OS command, LDAP, ORM-layer injections — still 38 CWEs and the highest CVE count on the list. XSS rides in this category too (high frequency, lower impact). The test loop is inputs and interpreters:

Code:
# SQL injection sweep on a parameterized-looking endpoint

sqlmap -u "https://target.tld/item?id=1" --batch --level 2 --risk 1 --forms

# Command injection detection - watch for reflected output

curl -s "https://target.tld/ping?host=127.0.0.1[;]id"

# XSS - reflect test across every input, check the response encoding

curl -s "https://target.tld/search?q=%3Csvg%3E" | grep "<script" || echo "REFLECTED RAW"

Fix: parameterized queries always, ORM raw-call audits, allowlist validation on every interpreter boundary, output encoding by context.

bam4g6.png


A06:2025 - INSECURE DESIGN

Flaws that no patch fixes because the architecture itself is wrong: password reset flows that let anyone enumerate users, missing rate limits on brute-force surfaces, business logic that allows negative quantity orders, trusts client-side state. The test is threat modeling before code — walk the abuse cases for each feature: what does a hostile user do with this flow if every field lies? Defenses belong at the design layer: separation of duties, rate limits as a requirement, safe failure defaults, resource quotas.

A07:2025 - AUTHENTICATION FAILURES

Credential stuffing succeeds because there is no lockout, session tokens never rotate after login, JWTs accept unsigned tokens, MFA is optional where it must be mandatory. Test:

Code:
# Credential stuffing simulation on your own app - controlled burst

hydra -L users.txt -P passwords.txt target.tld POST "/login" \

  "user=^USER^&pass=^PASS^" -f -t 4

# Session fixation - is the token rotated on login?

curl -sc jar.txt https://target.tld/login -d "u=a&p=b" -D - | grep -i "set-cookie"

# JWT weaknesses

jwt_tool <token> -C -d /usr/share/jwt_tool/jwt-secrets.txt

Enforce MFA on everything sensitive, rotate session IDs on privilege change, monitor for credential stuffing spikes, use established auth libraries — never hand-rolled token logic.

d2qqqz.png


A08:2025 - SOFTWARE OR DATA INTEGRITY FAILURES

Trust boundaries that were never verified: deserializing untrusted data, CI/CD pipelines that deploy unsigned artifacts, auto-update mechanisms without signature checks, JWTs accepted from cookies with no integrity validation, insecure CI/CD plugins. Test: inspect your own pipeline — can a compromised dependency push to main? Are releases signed? Does the app deserialize user-controlled blobs (ysoserial patterns, pickle in Python APIs)? Integrity checks at every hop where one system trusts another's output.

A09:2025 - SECURITY LOGGING AND ALERTING FAILURES

Events logged without being watched, logs that stop at application scope and miss the gateway, no alerting on auth failures or privilege changes. The test writes itself: perform five detectable actions — failed logins, IDOR probe, admin path access, permission change, data export — and then check whether any alert fired within five minutes. If your answer to "were we breached in March" requires a data forensics engagement, the logging layer failed before the breach did.

A10:2025 - MISHANDLING OF EXCEPTIONAL CONDITIONS

The new category. Stack traces returned to users with paths and queries, debug modes left on in production, failing open when the database or auth service times out, unchecked return values that silently skip security steps, missing-parameter handlers that proceed with defaults. Test: break things deliberately — kill the auth service, send malformed JSON, remove required fields — and read every response for leakages and unsafe continuations.

ud0w51.png


RUNNING THE FULL CHECKLIST IN ORDER

- Day 1 - A02 misconfig sweep plus A01 access control probes. Cheapest tests, highest yield. Gobuster for content discovery, header checks for hygiene, IDOR swaps on every object endpoint.

- Day 2 - A05 injection with sqlmap and Burp on every parameter; A07 auth testing with controlled burst and session analysis.

- Day 3 - A03 dependency audit across every lockfile, A04 TLS and storage review, A08 pipeline integrity walkthrough.

- Week 2 - A06 threat models per feature, A09 alert drill, A10 failure-injection pass. Re-run quarterly; the list changes when the data changes, and your app changes every deploy.

FAQ

- Q: Is the OWASP Top 10 a complete security checklist? A: No. It is the ten most common critical risks based on aggregated data — a starting floor, not a ceiling. Pair it with the OWASP ASVS levels for full coverage and the Cheat Sheet Series for per-category fixes.

- Q: What replaced SSRF in the OWASP Top 10? A: SSRF was absorbed into A01:2025 Broken Access Control — it is still tested and still exploitable, it just no longer has its own line. Tools mapping rules to the old A10:2021 should remap to A01.

- Q: What is the difference between the 2021 and 2025 OWASP Top 10? A: Two new categories (Software Supply Chain Failures, Mishandling of Exceptional Conditions), SSRF moved into A01, Security Misconfiguration promoted to #2, Injection down to #5, three renames, and 248 CWEs mapped versus 218 in 2021.

- Q: How often is the OWASP Top 10 updated? A: Roughly every three to four years — 2017, 2021, then 2025 announced at Global AppSec Washington with the final list in January 2026. The next cycle will follow new community-submitted test data.

- Q: Does passing the OWASP Top 10 mean my app is secure? A: It means the ten most common critical classes were checked. Insecure design, business logic abuse and authorization edge cases at the object level still require targeted threat modeling beyond the list.

RELATED ON BLACKHAT PAKISTAN

XSS Tutorial for Beginners - the reflection and encoding half of A05 Injection, tested payload by payload.

SQL Injection Tutorial - A05's highest-impact branch, from union selects to blind timing.

Burp Suite Tutorial - the intercept-and-replay workflow that runs most of this checklist manually.

Gobuster Tutorial 2026 - Day 1 content discovery for A02 misconfiguration.
 
Last edited:
Threads
1,086Threads
Messages
2,157Messages
Members
3,716Members
Latest member
allllalllalll45258Latest member
Top