← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 12, 2026 · 20:59via CVEFeed

CVE-2026-73491 - Loofah `allowed_uri?` does not detect `` URIs split by named whitespace character references

Brief

CVE ID : CVE-2026-73491

Published : Aug. 12, 2026, 8:59 p. m.

  • 5 minutes ago

Description : Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.

  • 0 until 2.
  • 2, Loofah::HTML5::Scrub. allowed_uri? does not reject URIs whose scheme is split or prefixed with the HTML5 named whitespace character references 	 or 
. CGI. unescapeHTML leaves those references intact, so allowed_uri?

reports the URL safe even though a browser decodes and strips the tab or line feed and executes the resulting URL. This issue affects only callers that pass HTML-encoded strings directly to allowed_uri? ; Loofah's default sanitize() path is not affected. This issue is fixed in version 2.

  • 2.

Severity: 0.0

  • NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed