Smashing the token limit with overlapping fragments

Refract AI Intelligence Digest

BLUF

A new fragmentation method allows attackers and testers to exceed standard token limits for data exfiltration.

NEWS

PortSwigger researchers introduced a collaboration with Alex to demonstrate how overlapping fragments can circumvent token restrictions. This advancement builds upon existing tools like DOM Invader to facilitate larger data extraction during security assessments.

Why I Care

Applications relying on token size limits for security controls may be vulnerable to increased data leakage, impacting both defensive postures and the efficacy of current scanning tools.

Next Steps

Security teams should audit token limit configurations and update web application firewalls to detect fragment-based anomalies by the end of Q4 2026.

I'm delighted to introduce Alex, my fellow swigger who I've collaborated with in the past with tools like DOM Invader. He showed me that it's possible to exfiltrate larger tokens than demonstrated in
Back to Blog Listing

Source: PortSwigger Research ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.