VYPR

luci-app-https-dns-proxy

by Openwrt

CVEs (1)

  • CVE-2026-67352Aug 1, 2026
    risk 0.00cvss epss 0.00

    luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS DNS Proxy status page, the resolver URL is rendered as raw HTML and executes…