CVE-2026-102333: httpdbg before 2.2.1 Stored Cross-Site Scripting via javascript URL
httpdbg before 2.2.1 fails to validate URL schemes in recorded HTTP request URLs rendered as clickable links in the web interface. Attackers controlling traffic recorded by httpdbg can supply javascript: scheme URLs that execute malicious scripts in the application origin when clicked, allowing access to captured request and response data including headers and tokens.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Users of the httpdbg web interface are exposed when they view recorded traffic containing an attacker-controlled request URL and click the rendered link. The issue can expose captured request and response data, including headers and tokens, to scripts running in the application's origin.
What must an attacker do to exploit it?
An attacker must be able to control traffic that httpdbg records and provide a URL using the javascript: scheme. Exploitation also requires a user to click the corresponding clickable link in the web interface.
Are installations on the fixed release affected?
No. The issue affects httpdbg versions before 2.2.1; version 2.2.1 is not listed as affected.