Medium severity6.1NVD Advisory· Published Sep 28, 2026
CVE-2026-102333
CVE-2026-102333
Description
httpdbg before 2.2.1 fails to validate URL schemes in recorded HTTP request URLs rendered as clickable links in the web interface. Attackers controlling traffic recorded by httpdbg can supply javascript: scheme URLs that execute malicious scripts in the application origin when clicked, allowing access to captured request and response data including headers and tokens.
Affected products
1Patches
Vulnerability mechanics
References
7- github.com/cle-b/httpdbg/blob/v2.2.0/httpdbg/hooks/recordhttp2.pynvd
- github.com/cle-b/httpdbg/blob/v2.2.0/httpdbg/webapp/static/index.htmnvd
- github.com/cle-b/httpdbg/commit/121845b41c19ddaf30b51be0797bc2ff4847d8b3nvd
- github.com/cle-b/httpdbg/issues/220nvd
- github.com/cle-b/httpdbg/pull/222nvd
- github.com/cle-b/httpdbg/releases/tag/v2.2.1nvd
- www.vulncheck.com/advisories/httpdbg-before-2.2.1-stored-cross-site-scripting-via-javascript-urlnvd
News mentions
0No linked articles in our index yet.