CVE-2026-73490
Description
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Prior to 2.25.2, Loofah's HTML5 sanitizer applies its local-reference restriction only to the xlink:href attribute on SVG use and feImage elements, while browsers also accept the plain href attribute. A crafted sanitized SVG can therefore reference an arbitrary same-origin external document; use may render external SVG content containing scripts or other dangerous content, and feImage may load external images for tracking. Applications that sanitize user-supplied SVG with Loofah's default allowlist are affected. This issue is fixed in version 2.25.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
loofahRubyGems | < 2.25.2 | 2.25.2 |
Affected products
17- Range: <2.25.2
- osv-coords16 versionspkg:apk/chainguard/gitlab-rails-ce-19.3pkg:apk/chainguard/gitlab-rails-ce-fips-19.3pkg:apk/chainguard/pgheropkg:apk/chainguard/pghero-fipspkg:apk/chainguard/ruby3.2-rails-7.2pkg:apk/chainguard/ruby3.2-rails-8.0pkg:apk/chainguard/ruby3.2-rails-8.1pkg:apk/chainguard/ruby3.3-rails-8.0pkg:apk/chainguard/ruby3.4-rails-7.2pkg:apk/chainguard/ruby3.4-rails-8.0pkg:apk/chainguard/ruby3.4-rails-8.1pkg:apk/chainguard/ruby4.0-rails-8.0pkg:apk/chainguard/ruby4.0-rails-8.1pkg:apk/wolfi/ruby3.2-rails-8.1pkg:apk/wolfi/ruby3.4-rails-8.1pkg:apk/wolfi/ruby4.0-rails-8.1
< 19.3.1-r6+ 15 more
- (no CPE)range: < 19.3.1-r6
- (no CPE)range: < 19.3.1-r3
- (no CPE)range: < 3.8.0-r4
- (no CPE)range: < 3.8.0-r4
- (no CPE)range: < 7.2.3.1-r8
- (no CPE)range: < 8.0.5-r7
- (no CPE)range: < 8.1.3-r9
- (no CPE)range: < 8.0.5-r10
- (no CPE)range: < 7.2.3.1-r10
- (no CPE)range: < 8.0.5-r7
- (no CPE)range: < 8.1.3-r11
- (no CPE)range: < 8.0.5-r6
- (no CPE)range: < 8.1.3-r10
- (no CPE)range: < 8.1.3-r9
- (no CPE)range: < 8.1.3-r11
- (no CPE)range: < 8.1.3-r10
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-9wjq-cp2p-hrgfghsaADVISORY
- github.com/flavorjones/loofah/commit/20867b9be689521887364b74822c41ef830523c9nvdWEB
- github.com/flavorjones/loofah/releases/tag/v2.25.2nvdWEB
- github.com/flavorjones/loofah/security/advisories/GHSA-9wjq-cp2p-hrgfnvdWEB
- github.com/flavorjones/loofah/pull/308nvd
News mentions
0No linked articles in our index yet.