loofah
RubyGems9 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting loofahpage 1 of 1
- CVE-2018-16468MEDIUMCVSS 5.4EG 5.4fixed in 2.2.32018-10-30
vulnerable: 0.2.0 ... 2.2.2 (29 versions)
In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
- CVE-2018-8048MEDIUMCVSS 6.1EG 6.1fixed in 2.2.12018-03-27
vulnerable: 0.2.0 ... 2.2.0 (27 versions)
In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attributes may occur in sanitized output by republishing a crafted HTML fragment.
- CVE-2019-15587MEDIUMCVSS 5.4EG 5.4fixed in 2.3.12019-10-22
vulnerable: 0.2.0 ... 2.3.0 (31 versions)
In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
- CVE-2022-23514HIGHCVSS 7.5EG 7.5fixed in 2.19.12022-12-14
vulnerable: 0.2.0 ... 2.9.1 (49 versions)
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah < 2.19.1 contains an inefficient regular expression that is susceptible to excessive backtracking when attempt…
- CVE-2022-23515MEDIUMCVSS 6.1EG 6.1fixed in 2.19.12022-12-14
vulnerable: 2.1.0 ... 2.9.1 (25 versions)
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.1.0, < 2.19.1 is vulnerable to cross-site scripting via the image/svg+xml media type in data URIs. This i…
- CVE-2022-23516HIGHCVSS 7.5EG 7.5fixed in 2.19.12022-12-14
vulnerable: 2.10.0 ... 2.9.1 (23 versions)
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.2.0, < 2.19.1 uses recursion for sanitizing CDATA sections, making it susceptible to stack exhaustion and…
- CVE-2026-73490MEDIUMCVSS 4.7EG 4.7fixed in 2.25.22026-08-12
vulnerable: 0.2.0 ... 2.9.1 (64 versions)
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Prior to 2.25.2, Loofah's HTML5 sanitizer applies its local-reference restriction only to the xlink:href attribute on…
- CVE-2026-73491LOWCVSS 2.3EG 2.3fixed in 2.25.22026-08-12
vulnerable: 2.25.0, 2.25.1
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: URIs whose scheme is split or…
- CVE-2026-73492LOWCVSS 2.3EG 2.3fixed in 2.25.22026-08-12
vulnerable: 2.25.0, 2.25.1
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: or vbscript: URIs whose schem…
Check whether loofah is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for loofah CVEs against the assets you own.
Book a Demo →