CVE-2026-73491 - Loofah `allowed_uri?` does not detect `` URIs split by named whitespace character references
Brief
CVE ID : CVE-2026-73491
Published : Aug. 12, 2026, 8:59 p. m.
- 5 minutes ago
Description : Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.
- 0 until 2.
- 2, Loofah::HTML5::Scrub. allowed_uri? does not reject URIs whose scheme is split or prefixed with the HTML5 named whitespace character references 	 or 
. CGI. unescapeHTML leaves those references intact, so allowed_uri?
reports the URL safe even though a browser decodes and strips the tab or line feed and executes the resulting URL. This issue affects only callers that pass HTML-encoded strings directly to allowed_uri? ; Loofah's default sanitize() path is not affected. This issue is fixed in version 2.
- 2.
Severity: 0.0
- NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
