Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: or vbscript: URIs whose scheme is split by semicolon-less numeric character references such as :, 	, 
, or 
. CGI.unescapeHTML leaves these references encoded, so allowed_uri? reports the URL safe even though a browser decodes an encoded colon or strips encoded whitespace and executes the resulting URI scheme. This issue affects only callers that pass HTML-encoded strings directly to allowed_uri?; Loofah's default sanitize() path is not affected. This issue is fixed in version 2.25.2. Join the discussion | CVE Database V5 | 08/12/2026, 21:00:24 UTC Added: 08/12/2026, 21:26:44 UTC |
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: URIs whose scheme is split or prefixed with the HTML5 named whitespace character references 	 or 
. CGI.unescapeHTML leaves those references intact, so allowed_uri? reports the URL safe even though a browser decodes and strips the tab or line feed and executes the resulting javascript: URL. This issue affects only callers that pass HTML-encoded strings directly to allowed_uri?; Loofah's default sanitize() path is not affected. This issue is fixed in version 2.25.2. Join the discussion | CVE Database V5 | 08/12/2026, 20:59:18 UTC Added: 08/12/2026, 21:13:14 UTC |
0 Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Prior to 2.25.2, Loofah's HTML5 sanitizer applies its local-reference restriction only to the xlink:href attribute on SVG use and feImage elements, while browsers also accept the plain href attribute. A crafted sanitized SVG can therefore reference an arbitrary same-origin external document; use may render external SVG content containing scripts or other dangerous content, and feImage may load external images for tracking. Applications that sanitize user-supplied SVG with Loofah's default allowlist are affected. This issue is fixed in version 2.25.2. Join the discussion | CVE Database V5 | 08/12/2026, 20:58:12 UTC Added: 08/12/2026, 21:13:14 UTC |
Loofah's allowed_uri? method fails to detect javascript: or vbscript: URIs when the scheme is split by numeric character references without trailing semicolons. Browsers decode these references and execute the URI, but allowed_uri? incorrectly marks them as safe. This affects callers that validate user-controlled URLs with allowed_uri? and then render them into browser-interpreted URI attributes, potentially enabling cross-site scripting (XSS). The default sanitize() method is not affected. The issue is fixed in Loofah version 2.25.2. Join the discussion | GCVE Database | 07/21/2026, 22:03:11 UTC Added: 07/22/2026, 00:11:12 UTC |
Loofah's HTML5 sanitizer did not restrict the SVG plain href attribute on certain elements, allowing references to arbitrary external documents. This bypasses the intended local-reference restriction applied only to the deprecated xlink:href attribute. The vulnerability affects applications sanitizing user-supplied SVG with Loofah versions prior to 2.25.2. Exploitation could lead to loading and rendering external SVG content with potential script execution in the context of the sanitized document or tracking via external images. Modern browsers limit cross-origin fetches, reducing but not eliminating risk. Upgrading to Loofah 2.25.2 or later mitigates this issue. Join the discussion | GCVE Database | 07/21/2026, 22:01:58 UTC Added: 07/22/2026, 00:11:12 UTC |
Showing 1 to 5 of 5 results