loofah vulnerabilities
CVEs whose affected-version data names the loofah package (rubygems). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-73491Low· 2.3Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: URIs whose scheme is split …
▾ Sunlitflavorjones · loofahEPSS 0.24%via NVD
GHSA-9wjq-cp2p-hrgfMedium· 4.7Loofah: SVG `href` attribute bypasses local-reference restriction
Loofah: SVG `href` attribute bypasses local-reference restriction
▾ Sunlitloofah · loofahvia GHSA
GHSA-5qhf-9phg-95m2LowLoofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons
Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons
▾ Sunlitloofah · loofahvia GHSA
GHSA-8whx-365g-h9vvLowLoofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references
Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references
▾ Sunlitloofah · loofahvia GHSA