Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-102333

MEDIUM NVD
CVSS Score 6.1
Severity MEDIUM
Published Sep 28, 2026
Vendor unknown

Description

httpdbg before 2.2.1 fails to validate URL schemes in recorded HTTP request URLs rendered as clickable links in the web interface. Attackers controlling traffic recorded by httpdbg can supply javascript: scheme URLs that execute malicious scripts in the application origin when clicked, allowing access to captured request and response data including headers and tokens.

References