Junglewise Threat Intelligence

CVE-2026-73490: Loofah HTML5 sanitizer SVG href attribute bypass

CVE-2026-73490 · Severity: medium · CVSS 4.7 · Published 2026-08-12

Technologies: Loofah. Vendors: RubyGems.

Executive brief

Loofah is a library used to sanitize HTML and XML documents. The HTML5 sanitizer failed to properly restrict the href attribute on SVG elements, allowing crafted SVG documents to reference external content. This could enable attackers to inject malicious SVG content, scripts, or tracking images into applications that use Loofah's default sanitization settings.

Technical details

Loofah's HTML5 sanitizer applied local-reference restrictions only to the xlink:href attribute on SVG use and feImage elements, but browsers also accept the plain href attribute. An attacker can craft a sanitized SVG document with a plain href attribute that references an arbitrary same-origin external document, bypassing the sanitizer's protections. This allows rendering of external SVG content containing scripts or other dangerous content, and feImage may load external images for tracking purposes. The vulnerability affects applications that sanitize user-supplied SVG with Loofah's default allowlist. The issue is fixed in version 2.25.2 via PR #308, which properly restricts SVG href attributes and updates URI validation to handle whitespace and numeric character references.

Affected products

  • Loofah Loofah prior to 2.25.2

Timeline

  • 2026-08-12: disclosed
  • 2026-07-15: patched

References

Related threats