CVE-2026-73491: CWE-184: Incomplete List of Disallowed Inputs in flavorjones loofah
Loofah versions from 2.25.0 up to but not including 2.25.2 contain a vulnerability where the allowed_uri? method does not properly reject javascript: URIs if the scheme is obfuscated with certain HTML5 named whitespace character references. This can lead to unsafe URLs being considered safe when passed as HTML-encoded strings directly to allowed_uri?. The default sanitize() method is not affected. The issue is fixed in version 2.25.2.
AI Analysis
Technical Summary
The vulnerability in flavorjones loofah (CVE-2026-73491) arises from incomplete filtering of disallowed inputs in the allowed_uri? method within versions 2.25.0 through 2.25.1. Specifically, javascript: URIs whose scheme is split or prefixed with HTML5 named whitespace character references such as 	 or 
 are not rejected because CGI.unescapeHTML does not decode these references, causing allowed_uri? to incorrectly mark them as safe. This flaw only affects callers passing HTML-encoded strings directly to allowed_uri? and does not impact the default sanitize() path. The vulnerability is resolved in version 2.25.2.
Potential Impact
The vulnerability allows certain javascript: URIs obfuscated with HTML5 named whitespace character references to bypass the allowed_uri? check, potentially leading to unsafe URLs being accepted as safe. However, this only affects specific usage patterns (direct calls to allowed_uri? with HTML-encoded input) and does not affect the default sanitization method. The CVSS 4.0 base score is 2.3, indicating a low severity impact with network attack vector, high attack complexity, and no privileges or user interaction required.
Mitigation Recommendations
Upgrade to loofah version 2.25.2 or later, where this issue is fixed. If upgrading is not immediately possible, avoid passing HTML-encoded strings directly to allowed_uri? and instead use the default sanitize() method, which is not affected by this vulnerability. Patch status is confirmed fixed in version 2.25.2.
CVE-2026-73491: CWE-184: Incomplete List of Disallowed Inputs in flavorjones loofah
Description
Loofah versions from 2.25.0 up to but not including 2.25.2 contain a vulnerability where the allowed_uri? method does not properly reject javascript: URIs if the scheme is obfuscated with certain HTML5 named whitespace character references. This can lead to unsafe URLs being considered safe when passed as HTML-encoded strings directly to allowed_uri?. The default sanitize() method is not affected. The issue is fixed in version 2.25.2.
CVSS v4.0
Score 2.3low
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in flavorjones loofah (CVE-2026-73491) arises from incomplete filtering of disallowed inputs in the allowed_uri? method within versions 2.25.0 through 2.25.1. Specifically, javascript: URIs whose scheme is split or prefixed with HTML5 named whitespace character references such as 	 or 
 are not rejected because CGI.unescapeHTML does not decode these references, causing allowed_uri? to incorrectly mark them as safe. This flaw only affects callers passing HTML-encoded strings directly to allowed_uri? and does not impact the default sanitize() path. The vulnerability is resolved in version 2.25.2.
Potential Impact
The vulnerability allows certain javascript: URIs obfuscated with HTML5 named whitespace character references to bypass the allowed_uri? check, potentially leading to unsafe URLs being accepted as safe. However, this only affects specific usage patterns (direct calls to allowed_uri? with HTML-encoded input) and does not affect the default sanitization method. The CVSS 4.0 base score is 2.3, indicating a low severity impact with network attack vector, high attack complexity, and no privileges or user interaction required.
Mitigation Recommendations
Upgrade to loofah version 2.25.2 or later, where this issue is fixed. If upgrading is not immediately possible, avoid passing HTML-encoded strings directly to allowed_uri? and instead use the default sanitize() method, which is not affected by this vulnerability. Patch status is confirmed fixed in version 2.25.2.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-12T19:00:33.735Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7ce1eabf8831d5392b0361
Added to database: 08/12/2026, 21:13:14 UTC
Last enriched: 08/12/2026, 21:27:21 UTC
Last updated: 08/13/2026, 01:32:46 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.