HIGH

CVE-2026-67352

2026-08-01 CVSS v3.1
CVSS
7.6

Description

luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS DNS Proxy status page, the resolver URL is rendered as raw HTML and executes JavaScript in the administrator's browser origin.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.21%
Probability of exploitation in next 30 days
12.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE