Stored Cross-Site Scripting in httpdbg Before 2.2.1
CVE-2026-102333
5.3MEDIUM
What is CVE-2026-102333?
The application httpdbg, prior to version 2.2.1, fails to properly validate URL schemes in HTTP request URLs that are rendered as clickable links in its web interface. This vulnerability enables attackers, who can manipulate traffic recorded by httpdbg, to inject malicious 'javascript:' scheme URLs. When these links are clicked, they can execute harmful scripts in the context of the application’s origin, potentially allowing unauthorized access to sensitive request and response data, including headers and authentication tokens.
Affected Version(s)
httpdbg 0 < 2.2.1
