Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-73492: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in flavorjones loofahCVE-2026-73492
0

CVE-2026-73492 is a low-severity cross-site scripting (XSS) vulnerability in the flavorjones loofah library versions 2.25.0 through 2.25.1. The flaw occurs in the Loofah::HTML5::Scrub.allowed_uri? method, which fails to reject javascript: or vbscript: URIs when their scheme is obfuscated using semicolon-less numeric character references. This can cause unsafe URLs to be incorrectly marked as safe, potentially leading to XSS if callers pass HTML-encoded strings directly to allowed_uri?. The default sanitize() method is not affected. The issue is fixed in version 2.25.2.

Join the discussion
CVE-2026-73491: CWE-184: Incomplete List of Disallowed Inputs in flavorjones loofahCVE-2026-73491
0

Loofah versions from 2.25.0 up to but not including 2.25.2 contain a vulnerability where the allowed_uri? method does not properly reject javascript: URIs if the scheme is obfuscated with certain HTML5 named whitespace character references. This can lead to unsafe URLs being considered safe when passed as HTML-encoded strings directly to allowed_uri?. The default sanitize() method is not affected. The issue is fixed in version 2.25.2.

Join the discussion
CVE-2026-73490: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in flavorjones loofahCVE-2026-73490
0

Loofah versions prior to 2.25.2 have a cross-site scripting vulnerability due to improper sanitization of SVG href attributes. The sanitizer only restricts xlink:href but browsers also accept href, allowing crafted SVGs to reference same-origin external documents that may contain malicious scripts or tracking images. This issue is fixed in version 2.25.2.

Join the discussion
Loofah: SVG `href` attribute bypasses local-reference restriction
0

Loofah's HTML5 sanitizer did not restrict the SVG plain href attribute on certain elements, allowing references to arbitrary external documents. This bypasses the intended local-reference restriction applied only to the deprecated xlink:href attribute. The vulnerability affects applications sanitizing user-supplied SVG with Loofah versions prior to 2.25.2. Exploitation could lead to loading and rendering external SVG content with potential script execution in the context of the sanitized document or tracking via external images. Modern browsers limit cross-origin fetches, reducing but not eliminating risk. Upgrading to Loofah 2.25.2 or later mitigates this issue.

Join the discussion
Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons
0

Loofah's allowed_uri? method fails to detect javascript: or vbscript: URIs when the scheme is split by numeric character references without trailing semicolons. Browsers decode these references and execute the URI, but allowed_uri? incorrectly marks them as safe. This affects callers that validate user-controlled URLs with allowed_uri? and then render them into browser-interpreted URI attributes, potentially enabling cross-site scripting (XSS). The default sanitize() method is not affected. The issue is fixed in Loofah version 2.25.2.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Package: pkg:gem/loofah
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses