{"id":"CVE-2026-102333","title":"httpdbg before 2.2.1 fails to validate URL schemes in recorded HTTP request URLs rendered as clickable links in the web interface","summary":"httpdbg before 2.2.1 fails to validate URL schemes in recorded HTTP request URLs rendered as clickable links in the web interface. Attackers controlling traffic recorded by httpdbg can supply javascript: scheme URLs that execute maliciou…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"cle-b","product":"httpdbg","affected":["httpdbg < 2.2.1"],"published":"2026-09-28","updated":"2026-09-28","sourceUpdated":"2026-09-28T23:17:01.677","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-102333","references":[{"url":"https://github.com/cle-b/httpdbg","label":"disclosure@vulncheck.com"},{"url":"https://github.com/cle-b/httpdbg/blob/v2.2.0/httpdbg/hooks/recordhttp2.py#L88-L97","label":"disclosure@vulncheck.com"},{"url":"https://github.com/cle-b/httpdbg/blob/v2.2.0/httpdbg/webapp/static/index.htm#L302","label":"disclosure@vulncheck.com"},{"url":"https://github.com/cle-b/httpdbg/commit/121845b41c19ddaf30b51be0797bc2ff4847d8b3","label":"disclosure@vulncheck.com"},{"url":"https://github.com/cle-b/httpdbg/issues/220","label":"disclosure@vulncheck.com"},{"url":"https://github.com/cle-b/httpdbg/pull/222","label":"disclosure@vulncheck.com"},{"url":"https://github.com/cle-b/httpdbg/releases/tag/v2.2.1","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/httpdbg-before-2.2.1-stored-cross-site-scripting-via-javascript-url","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-28T23:23:00.570Z","slug":"CVE-2026-102333","body":"## Overview\n\nhttpdbg before 2.2.1 fails to validate URL schemes in recorded HTTP request URLs rendered as clickable links in the web interface. Attackers controlling traffic recorded by httpdbg can supply javascript: scheme URLs that execute malicious scripts in the application origin when clicked, allowing access to captured request and response data including headers and tokens.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}