CVE-2026-73491: CWE-184: Incomplete List of Disallowed Inputs in flavorjones loofah
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: URIs whose scheme is split or prefixed with the HTML5 named whitespace character references 	 or 
. CGI.unescapeHTML leaves those references intact, so allowed_uri? reports the URL safe even though a browser decodes and strips the tab or line feed and executes the resulting javascript: URL. This issue affects only callers that pass HTML-encoded strings directly to allowed_uri?; Loofah's default sanitize() path is not affected. This issue is fixed in version 2.25.2.
AI Analysis
Technical Summary
The vulnerability in flavorjones loofah (CVE-2026-73491) arises from incomplete filtering of disallowed inputs in the allowed_uri? method within versions 2.25.0 through 2.25.1. Specifically, javascript: URIs whose scheme is split or prefixed with HTML5 named whitespace character references such as 	 or 
 are not rejected because CGI.unescapeHTML does not decode these references, causing allowed_uri? to incorrectly mark them as safe. This flaw only affects callers passing HTML-encoded strings directly to allowed_uri? and does not impact the default sanitize() path. The vulnerability is resolved in version 2.25.2.
Potential Impact
The vulnerability allows certain javascript: URIs obfuscated with HTML5 named whitespace character references to bypass the allowed_uri? check, potentially leading to unsafe URLs being accepted as safe. However, this only affects specific usage patterns (direct calls to allowed_uri? with HTML-encoded input) and does not affect the default sanitization method. The CVSS 4.0 base score is 2.3, indicating a low severity impact with network attack vector, high attack complexity, and no privileges or user interaction required.
Mitigation Recommendations
Upgrade to loofah version 2.25.2 or later, where this issue is fixed. If upgrading is not immediately possible, avoid passing HTML-encoded strings directly to allowed_uri? and instead use the default sanitize() method, which is not affected by this vulnerability. Patch status is confirmed fixed in version 2.25.2.
CVE-2026-73491: CWE-184: Incomplete List of Disallowed Inputs in flavorjones loofah
Description
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: URIs whose scheme is split or prefixed with the HTML5 named whitespace character references 	 or 
. CGI.unescapeHTML leaves those references intact, so allowed_uri? reports the URL safe even though a browser decodes and strips the tab or line feed and executes the resulting javascript: URL. This issue affects only callers that pass HTML-encoded strings directly to allowed_uri?; Loofah's default sanitize() path is not affected. This issue is fixed in version 2.25.2.
CVSS v4.0
Score 2.3low
Affected software
flavorjones
loofah
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in flavorjones loofah (CVE-2026-73491) arises from incomplete filtering of disallowed inputs in the allowed_uri? method within versions 2.25.0 through 2.25.1. Specifically, javascript: URIs whose scheme is split or prefixed with HTML5 named whitespace character references such as 	 or 
 are not rejected because CGI.unescapeHTML does not decode these references, causing allowed_uri? to incorrectly mark them as safe. This flaw only affects callers passing HTML-encoded strings directly to allowed_uri? and does not impact the default sanitize() path. The vulnerability is resolved in version 2.25.2.
Potential Impact
The vulnerability allows certain javascript: URIs obfuscated with HTML5 named whitespace character references to bypass the allowed_uri? check, potentially leading to unsafe URLs being accepted as safe. However, this only affects specific usage patterns (direct calls to allowed_uri? with HTML-encoded input) and does not affect the default sanitization method. The CVSS 4.0 base score is 2.3, indicating a low severity impact with network attack vector, high attack complexity, and no privileges or user interaction required.
Mitigation Recommendations
Upgrade to loofah version 2.25.2 or later, where this issue is fixed. If upgrading is not immediately possible, avoid passing HTML-encoded strings directly to allowed_uri? and instead use the default sanitize() method, which is not affected by this vulnerability. Patch status is confirmed fixed in version 2.25.2.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-12T19:00:33.735Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a7ce1eabf8831d5392b0361
Added to database: 08/12/2026, 21:13:14 UTC
Last enriched: 08/12/2026, 21:27:21 UTC
Last updated: 09/25/2026, 13:47:48 UTC
Views: 56
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.