CVE-2026-102333 Details
Description
httpdbg before 2.2.1 fails to validate URL schemes in recorded HTTP request URLs rendered as clickable links in the web interface. Attackers controlling traffic recorded by httpdbg can supply javascript: scheme URLs that execute malicious scripts in the application origin when clicked, allowing access to captured request and response data including headers and tokens.
A stored cross-site scripting vulnerability has been identified in httpdbg versions prior to 2.2.1. The issue arises because the application fails to properly validate URL schemes in recorded HTTP request URLs. This vulnerability allows attackers to inject JavaScript into the application by exploiting the HTTP/2 recording path. When the injected URL is clicked in the httpdbg web interface, the JavaScript executes in the context of the application, potentially accessing sensitive debugging information such as request and response headers, cookies, and authorization data.
Users can update to httpdbg version 2.2.1, which addresses the vulnerability by validating URL schemes before storing or rendering them as hyperlinks. The latest version can be downloaded from the Python Package Index (PyPI).
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cle-b/httpdbg/issues/220 | CISA-ADP | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/cle-b/httpdbg | [email protected] | Vendor |
| https://github.com/cle-b/httpdbg/blob/v2.2.0/httpdbg/hooks/recordhttp2.py#L88-L97 | [email protected] | Source CodeVendor |
| https://github.com/cle-b/httpdbg/blob/v2.2.0/httpdbg/webapp/static/index.htm#L302 | [email protected] | Source CodeVendor |
| https://github.com/cle-b/httpdbg/commit/121845b41c19ddaf30b51be0797bc2ff4847d8b3 | [email protected] | Source CodeVendor |
| https://github.com/cle-b/httpdbg/issues/220 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/cle-b/httpdbg/pull/222 | [email protected] | Issue TrackingVendor |
| https://github.com/cle-b/httpdbg/releases/tag/v2.2.1 | [email protected] | Release NotesVendor |
| https://www.vulncheck.com/advisories/httpdbg-before-2.2.1-stored-cross-site-scripting-via-javascript-url | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cle-b httpdbg | >= 0, < 2.2.1 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | CVE Modified | CISA-ADP |
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion