CVE-2026-102333
Received Received - Intake

javascript: Scheme URL Handling Flaw in httpdbg Web Interface

Vulnerability report for CVE-2026-102333, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulnCheck

Description

httpdbg before 2.2.1 fails to validate URL schemes in recorded HTTP request URLs rendered as clickable links in the web interface. Attackers controlling traffic recorded by httpdbg can supply javascript: scheme URLs that execute malicious scripts in the application origin when clicked, allowing access to captured request and response data including headers and tokens.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

httpdbg before 2.2.1 does not properly validate URL schemes in recorded HTTP requests displayed as clickable links in its web interface. Attackers who control recorded traffic can insert javascript: URLs that execute malicious scripts within the application's origin when clicked. This allows them to access captured request and response data, including sensitive headers and tokens.

Detection Guidance

Check if httpdbg versions before 2.2.1 are installed. Inspect web interface links for javascript: scheme URLs in recorded HTTP requests. Manually verify no malicious scripts execute when links are clicked.

Impact Analysis

If you use httpdbg before 2.2.1, clicking a malicious link in the web interface could allow an attacker to steal sensitive data like authentication tokens or session cookies from captured HTTP traffic. This could lead to unauthorized access to accounts or systems you interact with.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR's data protection principles or HIPAA's requirements for safeguarding protected health information. Organizations using affected versions may face compliance breaches and potential penalties.

Mitigation Strategies

Upgrade httpdbg to version 2.2.1 or later. Disable or restrict access to the web interface until updated. Review recorded sessions for suspicious javascript: URLs and remove them.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102333. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart