Vulnerabilities & PatchesEmerging1 src
CVE-2026-73491 - Loofah `allowed_uri?` does not detect `` URIs split by named whitespace character references
CVE ID : CVE-2026-73491
Published : Aug. 12, 2026, 8:59 p. m.
• 5 minutes ago
Description : Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2. 25. 0 until 2. 25. 2, Loofah::HTML5::Scrub. allowed_uri? does not reject URIs whose scheme is split or prefixed with the HTML5 named whitespace character references 	 or 
. CGI. unescapeHTML leaves those references intact, so allowed_uri?
reports the URL safe even though a browser decodes and strips the tab or line feed and executes the resulting URL. This issue affects only callers that pass HTML-encoded strings directly to allowed_uri? ; Loofah's default sanitize() path is not affected. This issue is fixed in version 2. 25. 2.
Severity: 0.0
• NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...