{"schema_version":1,"title":"loofah (RubyGems) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 14 vulnerabilities in loofah (RubyGems): 0 in the last 7 days and 6 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-73492, was published on 12 August 2026.","url":"https://junglewise.ai/threats/technologies/loofah","json_url":"https://junglewise.ai/threats/technologies/loofah.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/loofah","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":14,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":6,"last_365_days":8},"latest":[{"cve":"CVE-2026-73492","cvss":4,"epss":0.0039,"slug":"cve-2026-73492-loofah-xss-via-malformed-uri-scheme-with-numeric-character","title":"Loofah XSS via malformed URI scheme with numeric character references","severity":"medium","exploited":false,"published_at":"2026-08-12T22:17:16.527+00:00","url":"https://junglewise.ai/threats/cve-2026-73492-loofah-xss-via-malformed-uri-scheme-with-numeric-character"},{"cve":"CVE-2026-73491","cvss":4,"epss":0.0039,"slug":"cve-2026-73491-loofah-html5-scrub-javascript-uri-scheme-bypass","title":"Loofah HTML5 Scrub javascript URI scheme bypass","severity":"medium","exploited":false,"published_at":"2026-08-12T21:17:42.273+00:00","url":"https://junglewise.ai/threats/cve-2026-73491-loofah-html5-scrub-javascript-uri-scheme-bypass"},{"cve":"CVE-2026-73490","cvss":4.7,"epss":0.003,"slug":"cve-2026-73490-loofah-html5-sanitizer-svg-href-attribute-bypass","title":"Loofah HTML5 sanitizer SVG href attribute bypass","severity":"medium","exploited":false,"published_at":"2026-08-12T21:17:42.127+00:00","url":"https://junglewise.ai/threats/cve-2026-73490-loofah-html5-sanitizer-svg-href-attribute-bypass"},{"cvss":2.3,"slug":"loofah-xss-bypass-in-allowed-uri-via-malformed-character-references-ad120c57","title":"Loofah XSS bypass in allowed_uri? via malformed character references","severity":"low","exploited":false,"published_at":"2026-07-21T22:03:11+00:00","url":"https://junglewise.ai/threats/loofah-xss-bypass-in-allowed-uri-via-malformed-character-references-ad120c57"},{"cvss":4.7,"slug":"loofah-svg-href-attribute-bypass-in-html5-sanitizer-9f56b26b","title":"Loofah SVG href attribute bypass in HTML5 sanitizer","severity":"medium","exploited":false,"published_at":"2026-07-21T22:01:58+00:00","url":"https://junglewise.ai/threats/loofah-svg-href-attribute-bypass-in-html5-sanitizer-9f56b26b"},{"cvss":2.3,"slug":"loofah-xss-bypass-via-html5-named-character-references-in-allowed-uri-be76de4f","title":"Loofah XSS bypass via HTML5 named character references in allowed_uri?","severity":"low","exploited":false,"published_at":"2026-07-21T15:04:14+00:00","url":"https://junglewise.ai/threats/loofah-xss-bypass-via-html5-named-character-references-in-allowed-uri-be76de4f"},{"cvss":4,"slug":"loofah-has-improper-detection-of-disallowed-uris-via-allowed-uri-2566883c","title":"Loofah has improper detection of disallowed URIs via `allowed_uri?`","severity":"medium","exploited":false,"published_at":"2026-03-26T22:19:02+00:00","url":"https://junglewise.ai/threats/loofah-has-improper-detection-of-disallowed-uris-via-allowed-uri-2566883c"},{"cvss":4,"slug":"improper-detection-of-disallowed-uris-by-loofah-allowed-uri-62203f6f","title":"Improper detection of disallowed URIs by Loofah `allowed_uri?`","severity":"medium","exploited":false,"published_at":"2026-03-18T17:26:48+00:00","url":"https://junglewise.ai/threats/improper-detection-of-disallowed-uris-by-loofah-allowed-uri-62203f6f"},{"cve":"CVE-2022-23516","cvss":3.1,"epss":0.0113,"slug":"cve-2022-23516-uncontrolled-recursion-in-loofah","title":"Uncontrolled Recursion in Loofah","severity":"low","exploited":false,"published_at":"2022-12-13T17:40:50+00:00","url":"https://junglewise.ai/threats/cve-2022-23516-uncontrolled-recursion-in-loofah"},{"cve":"CVE-2022-23515","cvss":3.1,"epss":0.0083,"slug":"cve-2022-23515-improper-neutralization-of-data-uris-may-allow-xss-in-loofah","title":"Improper neutralization of data URIs may allow XSS in Loofah","severity":"low","exploited":false,"published_at":"2022-12-13T17:39:36+00:00","url":"https://junglewise.ai/threats/cve-2022-23515-improper-neutralization-of-data-uris-may-allow-xss-in-loofah"},{"cve":"CVE-2022-23514","cvss":3.1,"epss":0.0176,"slug":"cve-2022-23514-inefficient-regular-expression-complexity-in-loofah","title":"Inefficient Regular Expression Complexity in Loofah","severity":"low","exploited":false,"published_at":"2022-12-13T17:36:28+00:00","url":"https://junglewise.ai/threats/cve-2022-23514-inefficient-regular-expression-complexity-in-loofah"},{"cve":"CVE-2019-15587","cvss":3.1,"epss":0.0156,"slug":"cve-2019-15587-loofah-allows-cross-site-scripting","title":"Loofah Allows Cross-site Scripting","severity":"low","exploited":false,"published_at":"2019-11-05T23:58:25+00:00","url":"https://junglewise.ai/threats/cve-2019-15587-loofah-allows-cross-site-scripting"},{"cve":"CVE-2018-16468","cvss":3,"epss":0.0092,"slug":"cve-2018-16468-loofah-cross-site-scripting-vulnerability","title":"Loofah Cross-site Scripting vulnerability","severity":"low","exploited":false,"published_at":"2018-11-01T14:46:01+00:00","url":"https://junglewise.ai/threats/cve-2018-16468-loofah-cross-site-scripting-vulnerability"},{"cve":"CVE-2018-8048","cvss":3,"epss":0.0193,"slug":"cve-2018-8048-cross-site-scripting-in-loofah","title":"Cross-site Scripting in loofah","severity":"low","exploited":false,"published_at":"2018-03-21T11:57:11+00:00","url":"https://junglewise.ai/threats/cve-2018-8048-cross-site-scripting-in-loofah"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"nokogiri (RubyGems)","slug":"nokogiri","vulnerabilities":27,"url":"https://junglewise.ai/threats/technologies/nokogiri"},{"name":"rack (RubyGems)","slug":"rack","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/rack"},{"name":"oj (RubyGems)","slug":"oj","vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/oj"},{"name":"jquery-rails (RubyGems)","slug":"jquery-rails","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/jquery-rails"},{"name":"jquery-ui-rails (RubyGems)","slug":"jquery-ui-rails","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/jquery-ui-rails"},{"name":"openc3 (RubyGems)","slug":"openc3","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/openc3"},{"name":"lodash-rails (RubyGems)","slug":"lodash-rails","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/lodash-rails"},{"name":"net-imap (RubyGems)","slug":"net-imap","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/net-imap"},{"name":"action_text-trix (RubyGems)","slug":"action-text-trix","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/action-text-trix"},{"name":"camaleon_cms (RubyGems)","slug":"camaleon-cms","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/camaleon-cms"},{"name":"fluentd (RubyGems)","slug":"fluentd","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/fluentd"},{"name":"view_component (RubyGems)","slug":"view-component","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/view-component"}],"technology":{"hub":true,"name":"loofah (RubyGems)","slug":"loofah","vendor":{"name":"RubyGems","slug":"rubygems","url":"https://junglewise.ai/threats/vendors/rubygems"},"aliases":[],"homepage":"https://rubygems.org/gems/loofah","repo_url":"https://github.com/flavorjones/loofah","description":"Loofah is an HTML/XML manipulation and sanitization library for Ruby.","url":"https://junglewise.ai/threats/technologies/loofah"},"most_severe":[{"cve":"CVE-2026-73490","cvss":4.7,"epss":0.003,"slug":"cve-2026-73490-loofah-html5-sanitizer-svg-href-attribute-bypass","title":"Loofah HTML5 sanitizer SVG href attribute bypass","severity":"medium","exploited":false,"published_at":"2026-08-12T21:17:42.127+00:00","url":"https://junglewise.ai/threats/cve-2026-73490-loofah-html5-sanitizer-svg-href-attribute-bypass"},{"cvss":4.7,"slug":"loofah-svg-href-attribute-bypass-in-html5-sanitizer-9f56b26b","title":"Loofah SVG href attribute bypass in HTML5 sanitizer","severity":"medium","exploited":false,"published_at":"2026-07-21T22:01:58+00:00","url":"https://junglewise.ai/threats/loofah-svg-href-attribute-bypass-in-html5-sanitizer-9f56b26b"},{"cve":"CVE-2026-73492","cvss":4,"epss":0.0039,"slug":"cve-2026-73492-loofah-xss-via-malformed-uri-scheme-with-numeric-character","title":"Loofah XSS via malformed URI scheme with numeric character references","severity":"medium","exploited":false,"published_at":"2026-08-12T22:17:16.527+00:00","url":"https://junglewise.ai/threats/cve-2026-73492-loofah-xss-via-malformed-uri-scheme-with-numeric-character"},{"cve":"CVE-2026-73491","cvss":4,"epss":0.0039,"slug":"cve-2026-73491-loofah-html5-scrub-javascript-uri-scheme-bypass","title":"Loofah HTML5 Scrub javascript URI scheme bypass","severity":"medium","exploited":false,"published_at":"2026-08-12T21:17:42.273+00:00","url":"https://junglewise.ai/threats/cve-2026-73491-loofah-html5-scrub-javascript-uri-scheme-bypass"},{"cvss":4,"slug":"loofah-has-improper-detection-of-disallowed-uris-via-allowed-uri-2566883c","title":"Loofah has improper detection of disallowed URIs via `allowed_uri?`","severity":"medium","exploited":false,"published_at":"2026-03-26T22:19:02+00:00","url":"https://junglewise.ai/threats/loofah-has-improper-detection-of-disallowed-uris-via-allowed-uri-2566883c"},{"cvss":4,"slug":"improper-detection-of-disallowed-uris-by-loofah-allowed-uri-62203f6f","title":"Improper detection of disallowed URIs by Loofah `allowed_uri?`","severity":"medium","exploited":false,"published_at":"2026-03-18T17:26:48+00:00","url":"https://junglewise.ai/threats/improper-detection-of-disallowed-uris-by-loofah-allowed-uri-62203f6f"},{"cve":"CVE-2022-23514","cvss":3.1,"epss":0.0176,"slug":"cve-2022-23514-inefficient-regular-expression-complexity-in-loofah","title":"Inefficient Regular Expression Complexity in Loofah","severity":"low","exploited":false,"published_at":"2022-12-13T17:36:28+00:00","url":"https://junglewise.ai/threats/cve-2022-23514-inefficient-regular-expression-complexity-in-loofah"},{"cve":"CVE-2019-15587","cvss":3.1,"epss":0.0156,"slug":"cve-2019-15587-loofah-allows-cross-site-scripting","title":"Loofah Allows Cross-site Scripting","severity":"low","exploited":false,"published_at":"2019-11-05T23:58:25+00:00","url":"https://junglewise.ai/threats/cve-2019-15587-loofah-allows-cross-site-scripting"},{"cve":"CVE-2022-23516","cvss":3.1,"epss":0.0113,"slug":"cve-2022-23516-uncontrolled-recursion-in-loofah","title":"Uncontrolled Recursion in Loofah","severity":"low","exploited":false,"published_at":"2022-12-13T17:40:50+00:00","url":"https://junglewise.ai/threats/cve-2022-23516-uncontrolled-recursion-in-loofah"},{"cve":"CVE-2022-23515","cvss":3.1,"epss":0.0083,"slug":"cve-2022-23515-improper-neutralization-of-data-uris-may-allow-xss-in-loofah","title":"Improper neutralization of data URIs may allow XSS in Loofah","severity":"low","exploited":false,"published_at":"2022-12-13T17:39:36+00:00","url":"https://junglewise.ai/threats/cve-2022-23515-improper-neutralization-of-data-uris-may-allow-xss-in-loofah"}],"generated_at":"2026-09-26T17:07:00.185783+00:00"}