---
id: CVE-2026-102333
title: >-
  httpdbg before 2.2.1 fails to validate URL schemes in recorded HTTP request
  URLs rendered as clickable links in the web interface
summary: >-
  httpdbg before 2.2.1 fails to validate URL schemes in recorded HTTP request
  URLs rendered as clickable links in the web interface. Attackers controlling
  traffic recorded by httpdbg can supply javascript: scheme URLs that execute
  maliciou…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: cle-b
product: httpdbg
affected:
  - httpdbg < 2.2.1
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T23:17:01.677'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102333'
references:
  - url: 'https://github.com/cle-b/httpdbg'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/cle-b/httpdbg/blob/v2.2.0/httpdbg/hooks/recordhttp2.py#L88-L97
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/cle-b/httpdbg/blob/v2.2.0/httpdbg/webapp/static/index.htm#L302
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/cle-b/httpdbg/commit/121845b41c19ddaf30b51be0797bc2ff4847d8b3
    label: disclosure@vulncheck.com
  - url: 'https://github.com/cle-b/httpdbg/issues/220'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/cle-b/httpdbg/pull/222'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/cle-b/httpdbg/releases/tag/v2.2.1'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/httpdbg-before-2.2.1-stored-cross-site-scripting-via-javascript-url
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-28T23:23:00.570Z'
---

## Overview

httpdbg before 2.2.1 fails to validate URL schemes in recorded HTTP request URLs rendered as clickable links in the web interface. Attackers controlling traffic recorded by httpdbg can supply javascript: scheme URLs that execute malicious scripts in the application origin when clicked, allowing access to captured request and response data including headers and tokens.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
