VYPR

luci-app-https-dns-proxy

by Openwrt

CVEs (3)

  • CVE-2026-46368HigMay 26, 2026
    risk 0.61cvss 8.8epss 0.07

    luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt community packages feed and not installed by default — contains a command injection vulnerability in the setInitAction function. An…

  • CVE-2026-26899HigAug 27, 2026
    risk 0.50cvss 8.8epss 0.01

    An issue was discovered in luci-app-https-dns-proxy on OpenWrt PR #15 (< 2026-01-17). The setInitAction function in /usr/libexec/rpcd/luci.https-dns-proxy allows authenticated users to execute arbitrary shell commands via shell metacharacters in the name parameter

  • CVE-2026-67352HigAug 1, 2026
    risk 0.49cvss 7.6epss 0.00

    luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS DNS Proxy status page, the resolver URL is rendered as raw HTML and executes…