CVE-2026-67352
published 2026-08-01CVE-2026-67352: luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active…
PriorityP434high7.6CVSS 3.1
AVNACLPRLUIRSCCHILAN
EPSS
0.21%
12.1th percentile
luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS DNS Proxy status page, the resolver URL is rendered as raw HTML and executes JavaScript in the administrator's browser origin.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openwrt | luci | < * | * |
CVSS provenance
nvdv3.17.6HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
nvdv4.06.8MEDIUMCVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
OpenWrt LuCI HTTPS DNS Proxy Status Page resolver_url cross site scripting
vuldb·2026-08-01·CVSS 7.6
CVE-2026-67352 [HIGH] OpenWrt LuCI HTTPS DNS Proxy Status Page resolver_url cross site scripting
A vulnerability described as problematic has been identified in OpenWrt LuCI. This impacts an unknown function of the component HTTPS DNS Proxy Status Page. Executing a manipulation of the argument resolver_url can lead to cross site scripting.
This vulnerability is handled as CVE-2026-67352. The attack can be executed remotely. There is not any exploit available.
GHSA
luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML.
ghsa_unreviewed·2026-08-01
CVE-2026-67352 [MEDIUM] CWE-79 luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML.
luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS DNS Proxy status page, the resolver URL is rendered as raw HTML and executes JavaScript in the administrator's browser origin.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-01
Published