11 Total advisories
11 Vulnerabilities
0 Malware
Dependency scanning
Check whether loofah is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 4.7
CVE-2026-73490
Loofah: SVG `href` attribute bypasses local-reference restriction
UNKNOWN
CVE-2026-73491
Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references
UNKNOWN
CVE-2026-73492
Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons
UNKNOWN
GHSA-46fp-8f5p-pf2m
Improper detection of disallowed URIs by Loofah `allowed_uri?`
UNKNOWN
GHSA-2j22-pr5w-6gq8
Loofah has improper detection of disallowed URIs via `allowed_uri?`
MEDIUM 6.1
CVE-2022-23515
Improper neutralization of data URIs may allow XSS in Loofah
HIGH 7.5
CVE-2022-23514
Inefficient Regular Expression Complexity in Loofah
HIGH 7.5
CVE-2022-23516
Uncontrolled Recursion in Loofah
MEDIUM 6.1
CVE-2018-8048
Cross-site Scripting in loofah
MEDIUM 5.4
CVE-2019-15587
Loofah Allows Cross-site Scripting
MEDIUM 5.4
CVE-2018-16468
Loofah Cross-site Scripting vulnerability
Browse more RubyGems advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes