Stored Cross-Site Scripting in httpdbg Before 2.2.1
CVE-2026-102333

5.3MEDIUM

Key Information:

Vendor

Cle-b

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-102333?

The application httpdbg, prior to version 2.2.1, fails to properly validate URL schemes in HTTP request URLs that are rendered as clickable links in its web interface. This vulnerability enables attackers, who can manipulate traffic recorded by httpdbg, to inject malicious 'javascript:' scheme URLs. When these links are clicked, they can execute harmful scripts in the context of the application’s origin, potentially allowing unauthorized access to sensitive request and response data, including headers and authentication tokens.

Affected Version(s)

httpdbg 0 < 2.2.1

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

M.J Dhurgesh
.