๐Ÿ” CVE Alert

CVE-2026-73491

UNKNOWN 0.0

Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: URIs whose scheme is split or prefixed with the HTML5 named whitespace character references 	 or 
. CGI.unescapeHTML leaves those references intact, so allowed_uri? reports the URL safe even though a browser decodes and strips the tab or line feed and executes the resulting javascript: URL. This issue affects only callers that pass HTML-encoded strings directly to allowed_uri?; Loofah's default sanitize() path is not affected. This issue is fixed in version 2.25.2.

CWE CWE-184
Vendor flavorjones
Product loofah
Published Aug 12, 2026
Stay Ahead of the Next One

Get instant alerts for flavorjones loofah

Be the first to know when new unknown vulnerabilities affecting flavorjones loofah are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

flavorjones / loofah
>= 2.25.0, < 2.25.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/flavorjones/loofah/security/advisories/GHSA-8whx-365g-h9vv github.com: https://github.com/flavorjones/loofah/pull/308 github.com: https://github.com/flavorjones/loofah/commit/5e91af861e3cdab47b91dd0b81f3afdfd13a5e19 github.com: https://github.com/flavorjones/loofah/releases/tag/v2.25.2