๐Ÿ” CVE Alert

CVE-2026-73492

UNKNOWN 0.0

Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: or vbscript: URIs whose scheme is split by semicolon-less numeric character references such as &#58, &#9, &#10, or &#13. CGI.unescapeHTML leaves these references encoded, so allowed_uri? reports the URL safe even though a browser decodes an encoded colon or strips encoded whitespace and executes the resulting URI scheme. This issue affects only callers that pass HTML-encoded strings directly to allowed_uri?; Loofah's default sanitize() path is not affected. This issue is fixed in version 2.25.2.

CWE CWE-79 CWE-184
Vendor flavorjones
Product loofah
Published Aug 12, 2026
Stay Ahead of the Next One

Get instant alerts for flavorjones loofah

Be the first to know when new unknown vulnerabilities affecting flavorjones loofah are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

flavorjones / loofah
>= 2.25.0, < 2.25.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/flavorjones/loofah/security/advisories/GHSA-5qhf-9phg-95m2 github.com: https://github.com/flavorjones/loofah/pull/308 github.com: https://github.com/flavorjones/loofah/commit/f1be9d893b5a8dd79240441a912d8897e74c38c0 github.com: https://github.com/flavorjones/loofah/releases/tag/v2.25.2